Cyber Security Incident Response Procedure
v2.0
Purpose. This procedure sets out how suspected and confirmed cyber security incidents are identified, contained, eradicated, recovered from and reported.
1.Scope
This procedure applies to any event that threatens the confidentiality, integrity or availability of a client or Nova system, including phishing, malware, ransomware, unauthorised access, lost devices and data leakage. It applies to all staff, with the Cyber Security team leading the response.
2.Identification
Alerts from endpoint protection, email security, identity platforms and user reports must be triaged by a security analyst within 30 minutes during business hours and within one hour on call. The analyst must confirm whether an incident has occurred, classify its severity and record it in the Security Incident Register. Evidence such as logs, email headers and screenshots must be preserved before any clean up.
- Triage within 30 minutes
- Classify severity from one to four
- Record in the Security Incident Register
- Preserve evidence before acting
3.Containment
Containment actions will be chosen to stop the spread with the least disruption, such as isolating the endpoint, disabling the account, revoking sessions, blocking the sender or domain and resetting credentials. Containment for severity one and two incidents must be approved by the Cyber Security Lead and recorded as an emergency change.
4.Eradication and recovery
The root cause must be removed, such as removing malware, closing the vulnerability or removing the mail rule created by the attacker. Systems will be restored from clean backups where required and monitored closely for seven days. The client must be told what was done in plain language.
5.Notification
The client's authorised contact must be notified of every confirmed incident on the day it is confirmed. Where personal information is involved the Business Services Manager must assess whether the notifiable data breaches scheme applies and support the client to notify affected individuals and the Office of the Australian Information Commissioner within the required time.
6.Post incident review
Every severity one and two incident will have a post incident review within ten business days covering timeline, cause, response effectiveness and improvements. Actions will be recorded in the register and tracked to completion.