Incident Management Standard (SFA 06-107.2.6)

Quick Overview
  • This standard sets the specific requirements for how SFA prepares for, responds to, communicates about, and reports security incidents (events that threaten SFA data, systems, or IT facilities).
  • It carries out the goals in the SFA 06-107.2 Information Security Technology Policy.
  • Most requirements are carried out by security and IT leadership (the CISO, the Office of Information Security, IT teams, and Privacy Officers), but every user has a part to play by reporting suspected incidents promptly.
  • These requirements are the minimum baseline SFA must meet; the university may choose to do more.
  • Meeting this standard is mandatory unless a formal exception is granted.

A "security incident" is any known or suspected event that could harm SFA's data, systems, or IT facilities, from a lost laptop or a phishing click to a full data breach. This standard spells out what the university must do to be ready: train the right people, test its response plans, handle incidents in a consistent way, communicate quickly and carefully, and report incidents to the right internal and external authorities on time. The goal is to catch problems early, limit the damage, recover quickly, and learn from every incident.

i
Policy vs. Standard
The matching policy (06-107.2) says what SFA wants to achieve. This standard says how, the concrete requirements. Day-to-day steps live in procedures.

Who This Applies To

This standard applies to all SFA employees, users, third-party service providers, research partners, and other authorized users of SFA information resources. The detailed response and reporting requirements below are carried out mostly by the people who run the security and IT programs: the CISO, the Office of Information Security, IT teams, Privacy Officers, and designated incident responders. Everyday users have one key job, described below: report anything suspicious right away.

i
Baseline, not a ceiling
Everything here is the minimum SFA must do. Departments may add stricter requirements, but never anything weaker. See the SFA 06-107 Controls Crosswalk for higher control tiers.

Who Is Responsible

Key roles & responsibilities ⌄
A note on names: At SFA, the senior information security role is the Chief Information Security Officer (CISO). There is no separate "Information Security Officer" position. The abbreviation ISO at SFA refers to the Office of Information Security (the office that supports the CISO), not to a person.
  • Chief Information Security Officer (CISO) & Office of Information Security: Develops, enforces, and maintains the incident management process; directs investigations during and after incidents; oversees any outside incident response vendors; works with Privacy Officers to scope data breaches; prepares after-action reports (lessons learned) for executive leadership; and keeps forensic evidence and full, independent access to all incident logs.
  • Information Resource Manager (IRM): Directs the restoration of systems based on business priorities and technical feasibility, and secures the resources (hardware, software, or contractors) needed to get systems back online.
  • Agency Head: Appoints a senior executive (someone other than the IRM or CISO) to serve as the Incident Commander.
  • Incident Commander: Coordinates incident information across the executive team (suspected cause, business impact, estimated recovery time) and relays business priorities for restoration to the IRM, without pulling response staff away from their work.
  • Security Response Teams / Stakeholders: Follow the Incident Commander's direction to respond to and contain incidents according to their nature and severity, and share incident information with the right people in a timely way.
  • Privacy Officers (PO): Make sure incident handling complies with privacy laws; direct any breach-notification activity; advise leadership on confirmed breaches; and coordinate with outside breach counsel when one is used. (At some institutions the Privacy Officer role sits with legal or compliance staff.)
Full role definitions Complete responsibilities for each role are in the attached standard PDF.

What This Standard Requires

The requirements are grouped into four areas. Expand any area for a plain-language summary of what it requires. The official requirement numbers (like 06-107.2.6.1.1) are shown so you can match them to the attached PDF.

1  Security Incident Planning  Getting ready before anything happens ⌄

SFA must prepare in advance: train responders, build a written response plan, test it, and put tools in place so incidents are caught and handled consistently.

  • Give incident-response training to people with response roles before they start, when systems change, and at least once every 12 months; review and update that training yearly (06-107.2.6.1.1).
  • Make sure the training covers the essentials: how to respond to a data breach, how and to whom to report incidents (internally to the CISO and externally to residents, law enforcement, and state/federal agencies), how to work with outside responders and insurance, and post-incident cleanup (06-107.2.6.1.2).
  • Test the incident-response capability for critical systems at least once every 12 months, using checklists, walk-through or tabletop exercises, and simulations (06-107.2.6.1.3).
  • Identify, document, and coordinate the specific people and groups who must be involved in response and testing (06-107.2.6.1.4).
  • Build an incident-handling capability that covers preparation, detection, analysis, containment, recovery, and user response, including insider-threat handling, coordination with risk management and disaster recovery, evidence collection, lessons learned, and consistent results across the institution (06-107.2.6.1.5).
  • Use automated tools to identify, contain, track, and report incidents wherever it is technically feasible (06-107.2.6.1.6).
  • Track and document every security incident, its status, and relevant details using a defined process or tracking tool (06-107.2.6.1.7).
  • Develop a written incident response plan (a roadmap that defines reportable incidents, categorizes them, sets metrics and resources, addresses information sharing, and is reviewed at least yearly), then distribute it, keep it current, communicate changes, and protect it from unauthorized access (06-107.2.6.1.8).
  • For breaches involving confidential data, build in a process to decide whether notice is required, assess the harm to affected individuals, and identify the privacy rules that apply, working with Data Protection and Privacy Officers (06-107.2.6.1.9).
  • Test the response capability with automated tools where feasible, and use results from tests and real incidents to continuously improve (06-107.2.6.1.10).
  • Set up the ability to coordinate with outside service providers, and name the staff authorized to request and receive their support (06-107.2.6.1.11).
2  Response to Security Incidents  Acting when a breach happens ⌄

When a data breach or unauthorized disclosure occurs, SFA must respond in a defined, step-by-step way to contain it and stop it from spreading.

  • Respond to a data breach by assigning responders, identifying exactly which data was affected, alerting the CISO and IT teams through a channel not touched by the breach, isolating the affected system, removing the exposed data, and checking for other systems that may also have been compromised (06-107.2.6.2.1).
3  Security Incident Communication  Sharing information carefully ⌄

SFA must share incident information with the right people quickly, while protecting sensitive details and coordinating public communications.

  • Coordinate and share incident details internally and externally to build a fuller picture and a better response; notify the SFA CISO of a significant attack within 12 hours of detection and share indicators of compromise and attacker techniques within 6 hours, treating that information as highly confidential and de-identifying it (with Privacy Officers) before any external sharing (06-107.2.6.3.1).
  • Manage public relations around an incident and protect the university's reputation, coordinating outside communications with the right offices (Marketing Communications, the Office of General Counsel, and executive leadership) and meeting notification requirements (06-107.2.6.3.2).
4  Security Incident Reporting  Telling the right authorities, on time ⌄

SFA must have clear processes for staff to report incidents internally and for the university to report them to outside regulators within required deadlines.

i
Suspect an incident? Report it right away
If you think a device, account, or data may be compromised (a lost laptop, a phishing click, an unexpected file exposure), contact the IT Help Desk at (936) 468-4357 (HELP) or help.sfasu.edu. The Help Desk connects you to the incident-response team. When in doubt, report it: it is always better to raise a false alarm than to stay silent.
  • Set up an internal process for users to report suspected and confirmed incidents to the CISO, Privacy Officers, and other responders; submit qualifying incidents into the SFA Incident Response application (for example: unauthorized access to or disclosure of confidential data, a lost or stolen unencrypted device, a service disruption lasting more than a day, possible legal or cyber-liability issues, reputational harm, or vendor incidents); and coordinate with the Office of General Counsel and Privacy Officers to report to external regulators (such as Texas DIR/TAC 202, GDPR, and HIPAA) within required timeframes (06-107.2.6.4.1).
  • Provide a support resource that gives users advice and assistance on handling and reporting incidents (this is the front door general users reach through the Help Desk) (06-107.2.6.4.2).
  • Report confirmed incidents to the Texas Department of Information Resources (DIR) within 48 hours of confirmation, whether or not they are fully fixed, including the nature and scope, the individuals and records involved, the likely cause, containment steps, and a contact; the CISO ensures this deadline is met, and every DIR notice is logged and retained (06-107.2.6.4.3).
  • Report system vulnerabilities found during or tied to an incident to the defined staff (such as the CISO and system owners) so they can be tracked and fixed (06-107.2.6.4.4).

Conformance & Exceptions

Meeting this standard is mandatory and effective as of the standard's publication, unless a written contract says otherwise or a formal exception has been granted. If a requirement genuinely can't be met and there's no workable fix, follow the exception process in the SFA 06-107.2 Information Security Technology Policy; requests go to the SFA Chief Information Security Officer (CISO).

!
Important
Violations of SFA 06-107 may lead to disciplinary action, up to and including involuntary separation from employment.

Compliance Mapping (Reference)

For auditors and security staff. Everyday users can skip this section.

Frameworks & control references ⌄

Requirements in this standard map to one or more of these authoritative sources:

  • NIST 800-53 Rev 5.1.1, especially the IR (Incident Response) and SI control families.
  • TAC 202, Subchapter C, for example 202.73 and 202.74(a)(2)(A).
  • Texas DIR Security Controls Catalog, for example IR-2 through IR-9 and SI-7.
  • NIST CSF (Respond and Recover functions) and NIST 800-171 (3.6.1, 3.6.2, 3.6.3).
  • UTS 165 (for example 12.2, 12.3, 12.4, 12.6).
  • Privacy and sector frameworks where relevant: HIPAA, GLBA, GDPR (Articles 32, 33, 34), and FERPA (PTAC Data Breach Response Checklist).

The full requirement-by-requirement control mapping is in the attached standard PDF and the SFA 06-107 Controls Crosswalk.

Related Policies & Standards

Supporting policy: SFA 06-107.2 Information Security Technology Policy

Related standards:

Other references:

  • UTS 172 Emergency Management Policy
  • SFA 06-107 Controls Crosswalk Reference
  • HIPAA Breach Notification Rule · FERPA PTAC Data Breach Response Checklist
  • Hospital Incident Command System (HICS) · FEMA National Incident Management System · UT System Incident Tracking Tool

Responsible office: Office of Information Security  ·  Contact: itsecurity@sfasu.edu

📎
Official document
The complete, official standard is attached to this article as a PDF, including its full requirement text, role definitions, and control mappings. This article summarizes that standard in plain language. If anything in this article conflicts with the attached PDF, the PDF is the official version and takes precedence.

Need Help?

Contact the IT Help Desk at (936) 468-4357 (HELP) or submit a ticket at help.sfasu.edu. For questions about this standard, contact the Office of Information Security at itsecurity@sfasu.edu.
Print Article

Related Articles (3)

Definitions of the key terms used throughout the SFA 06-107 information security program; any term shown in italics in a policy or standard is defined here.
Sets SFA's objectives for the technical safeguards that protect its systems, devices, and data, covering access, asset management, system development, continuity and disaster recovery, security monitoring, and incident response; carried out by Standards 06-107.2.1 through 06-107.2.6.
Sets SFA's objectives for identifying and managing the security and privacy risks introduced by vendors and third-party services, from pre-purchase review through ongoing oversight; carried out through the Cybersecurity Risk Management (06-107.1.2) and Personnel & Third-Party Security (06-107.1.3) Standards.