Incident response management policy is very important in minimizing the damage from an incident and in recovering the operations at the earliest possible juncture.
Roles and responsibilities for incident management should be clearly defined. The following are some of the important functions relating to incident management:
- A coordinator to liaison with process owners
- An executive officer to oversee the incident response capability
- Security experts to investigate the incident
- A public relations team to manage the reputation for both internal and external stakeholders
The incident reporting procedure should be clearly defined, documented, and made available to all employees and relevant stakeholders.
Teams of experts should be available to investigate the incident to arrive at the root cause for preventive action. To address incidents properly, it is necessary to collect evidence as soon as possible after the occurrence. Legal advice may be needed in the process...