Purpose
All authorized users have an interest in the security of the computer resources at Georgia Southern University, and share in the responsibility for protection of those resources, prevention of problems, and incident detection and response. The purpose of this document is to describe the general procedures that will be followed in response to a security incident involving University resources. Cooperation of personnel with these procedures is mandatory. A security incident is defined as a threat to the legitimate use and/or operation of any University computing resource as defined in the Computer Use Policies, or the actual occurrence of any situation identified as a potential risk to those resources. Threats may be internally or externally generated.
Security Incident Response Team
Security incidents will be responded to by a specially-formed team of individuals from across the University, the Security Incident Response Team (SIRT). This team will be comprised of technical resources with the appropriate skills to identify, assess, respond to and communicate the effects of security incidents. SIRT members will be designated by the Director of Information Technology Services who is authorized as the designee of the Chief Information Officer, as per the Computer Use Policies, to take any and all necessary actions, including immediate confiscation and/or disabling of a University computer resource or the temporary termination of a computer account, to protect, investigate, and ensure the security and proper use of the computer resources. Full cooperation with the SIRT is required of all authorized users of Georgia Southern University computer resources.
Security Incident Response
Generally speaking, security incidents will be responded to by removing or deactivating the threat or cause of the problem as soon as possible and as completely as possible while investigative and corrective actions are taken. In addition, appropriate measures to support investigation of the incident will be taken. Cooperation of authorized users with these steps is required. Specifically, incident response procedures will include the following practices as appropriate.
External Notification of Security Incidents
Release of information regarding a security incident beyond the offices and individuals named above must be coordinated through the Office of Public Relations and Office of Legal Affairs. If the security incident involves an attack from a known outside entity, that entity should be contacted by a representative of the SIRT with notification that the incident occurred and a request for information on what measures will be taken to prevent subsequent incidents.
| |
Organization
|
Instruction
|
Students |
Scholarship
|
Service |
Faculty
Personnel |
| Policies | Searches | Legal | Financial | News | Comments | |