Sie sind auf Seite 1von 1

SECURITY INCIDENT RESPONSE (SHORT FORM) Page _____ of _____

The following is a sample incident report. The report is an example of the types of information and incident details that will be used to track and
report security incidents for CSU. The format of this report is subject to change as reporting standards and capabilities are further developed.

Contact Information and Incident


Last Name: First Name:
Job Title:
Phone: Alt Phone:
Mobile: Pager:
Email: Fax:

Incident General Information


Incident #: Source of External Type of Incident: Malware
Incident: Internal
Date/Time of Date/Time of
Incident Occurred: Incident Detected:
Campus/Site: Severity Level: Low
Impact Category: Campus Only Confidential/Personal Identifiable Information Yes No
Affected?
Systems and Services Impacted: [Affected systems and services]

Incident Summary
Comments Example … Received numerous reports of Trojan distribution email. The mail messages contained a
link to angelfire.com. This site contained pages with code to exploit a recent vulnerability in IE 6.
Accessing the pages forced a download of a SubSeven variant. Approximately 20 employees were
affected.

Incident Mitigation
Comments: Example …Desktop malware detection signatures updated and deployed. Angelfire website has been
taken offline and blocked at network egress points.

Recommendation
Comments: [Follow-on actions recommended to be taken, if any.]

Additional Comments/Notes
Comments: [Any additional notes, information or observations related to the security incident or this report.]

File=secincidentrespshortform.doc (Confidential) [Rev: Mar-05]

Das könnte Ihnen auch gefallen