QGEA
PUBLIC
Information security incident management guideline
Employees Event/Incident Sent
Feedback Received
QGCIO Incident category guideline
Register Event/ Incident
Initial Diagnosis
Classify Incident
Determine Action
Conduct Internal Investigation
AGENCY
Event/Incident detected
ISIRT
Event/ Incident Register
Advise QGISVRT If significant event
Notify Information Asset Owner
Advise QGISVRT request If incident QGISVRT may effect assistance other agencies
resolvable internally
Resolve Problem
Close Incident
Provide Feeback
no further analysis required/ available
Collate Report
not resolvable internally Event/ Incident Register
Seek External Support
forensic analysis capability update QGISVRT
Post Incident Forensic Analysis
request QGISVRT assistance Escalate Internally
Other Areas (CIO, CEO, HR, Internal Governance)
Incident Report Received
Analyse for WoG impact Communicate potential impact to agencies
Analyse for WoG impact Communicate potential impact to agencies
Communicate update to agencies
AGENCIES
QGISVRT
OUTSIDE THE SCOPE OF THIS GUIDELINE
Figure 4: Information security incident response process model
Final | v2.0.0 | August 2013
Page 12 of 26 PUBLIC