SECURITY INCIDENTS MANAGEMENT
Objective:
To standardize a system and to assign responsibilities for identification and resolution of non conformities associated with the implementation and operation of ISMS
To analyze and evaluate the causes of non- conformities
To establish and specify systematic steps for implementation and verification of corrective / preventive actions
To create a permanent solution that prevents recurrence of non-conformities or potential non-conformities
Description:
Reporting of security incidents to the CISO through a defined mechanism
Quick actions in the form of investigation by a top level investigation committee in case of serious security incidents
Rectification of minor security events through CARs against the individual or departments
Recording of lesson learned to serve as a reference for continual improvement of ISMS at KKI in the future
Constant training to the staff to create as much awareness about security incidents and to protect their occurrence