preview

LSNB Incident Response

Decent Essays

Policy

General Requirements
This policy establishes the following general requirements:

A LSNB Incident Response Team (IRT) will be implemented. By approving this policy, the board grants the IRT authority to act and make decisions as necessary to appropriately respond to an incident.

• LSNB IRT members have defined roles and responsibilities, which are outlined in the Incident Response Procedures. These responsibilities will take priority over normal duties in the event of a security incident.
• An event classification system, which defines incidents by their level of severity, will used to manage the incident response process and provide guidance for escalation.
• Whenever a security incident of a physical or electronic nature is …show more content…

The event will have little, if any, material impact on LSNB’s operations or reputation. Examples of low level events include sharing of passwords, policy or procedural violations, and scans of LSNB systems (except online banking or investing systems, which are medium level events).

Incident Reporting

All LSNB staff and contractors are responsible for helping to ensure the security of the information systems that they use and operate. Part of this responsibility is the duty to report any confirmed or suspected security problem in a timely manner. Any suspicion or detection of a computer or IT-related security problem is to be reported to the LSNB’s ISO or the Chief Risk Officer. Any suspicion or detection of a physical security problem is to be reported to the LSNB’s Security Officer.

Incident Response and Escalation

Detection and identification of a suspected incident represents the first step of the incident response process. The response process is characterized by four …show more content…

Sensitive customer information also includes any combination of components of customer information that would allow someone to log onto or access the customer’s account, such as user name and password or password and account

Get Access