Information Assurance: Managing Organizational IT Security Risks

Understand what constitutes an IA incident
Discuss what members comprise the incident handling team
Determine a measured approach and appropriate procedures for incident handling
The best-laid defenses will eventually fail. When that happens, the security team needs to turn to preexisting battle plans.... The incident response plan needs to be in place before it is needed. The critical steps that should be included in the incident response plan are: regain control of the situation, analyze the intrusion, recover from the incident, improve your security to prevent the same type of attack, reconnect to the Internet, and update the security policy to reflect changes (Miller, 2001, p. 5).
It is critical that all users understand what constitutes an IA incident, not only to avoid committing incidents, but to know how to recognize and report IA incidents when they occur. An IA incident could be any event that has an actual or potentially adverse affect on information or information systems. Think of the incident as the symptom; the cause of the incident is a threat. An IA incident may also involve a violation of law. The following are examples of realized threats that result in IA incidents:
A virus-infected e-mail attachment executes upon opening, deleting critical system files
A disgruntled employee maliciously modifies or destroys critical information
An unscheduled power interruption causes a denial of service
A system administrator abuses his privileged access by gaining unauthorized access to...