36 MAC Pt. 1, R. 9.1
Incident Response Management
Cite as 36 Miss. Admin. Code Pt. 1, R. 9.1
Incident Response Management
A. Each agency must establish and maintain an incident response process that addresses
roles and responsibilities, compliance requirements, and a communication plan.
1. Each agency must ensure that their incident response process is appropriately
aligned with the State of MS’s Enterprise Cybersecurity Incident Response
Plan. The enterprise plan can be found on the ITS website (www.its.ms.gov).
2. Review the incident response process annually, or when significant agency
changes occur that could impact this safeguard. This may include changes to
network architecture which may affect business continuity, perceived or
realized security events, or other modifications to an agency's infrastructure
which alter business flow.
3. In addition to maintaining an electronic version of the incident response plan,
all agencies must prepare a hard copy which is maintained and accessible to
appropriate staff.
B. Each agency must designate one key person, and at least one backup, who will
manage the agency’s incident handling process.
1. Management personnel are responsible for the coordination and
documentation of incident response and recovery efforts and can consist of
employees internal to the enterprise, third-party vendors, or a hybrid
approach. If using a third-party vendor, designate at least one person internal
to the agency to oversee any third-party work. All agencies must document
whether incident response is handled internally or via a third-party vendor and
shall retain any documentation describing agreements made with external
service providers.
2. Review the management personnel designations annually, or when significant
agency changes occur that could impact this safeguard.
C. Each agency must assign key roles and responsibilities for incident response,
including staff from legal, IT, information security, facilities, public relations, human
resources, incident responders, and analysts, as applicable. All assignments must be
documented as a component of the agency Incident Response plan.
1. Review key roles and responsibilities annually, or when significant agency
changes occur that could impact this safeguard.
D. Each agency must determine which primary and secondary mechanisms will be used
to communicate and report during a security incident. Mechanisms can include phone
calls, emails, or letters. Keep in mind that certain mechanisms, such as emails, can be
affected during a security incident.
1. Review communication mechanisms annually, or when significant agency
changes occur that could impact this safeguard.
E. Each agency must track, document, and report incidents to designated officials and/or
authorities both internal and external to the agency.
1. Establish and maintain contact information for parties that need to be
informed of security incidents. Contacts may include internal staff, third-party
vendors, law enforcement, cyber insurance providers, relevant government
agencies, or other stakeholders. Verify contacts annually to ensure that
information is up to date.
2. Establish and maintain an agency process for the workforce to report security
incidents. The process includes reporting timeframe, personnel to report to,
mechanism for reporting, and the minimum information to be reported. Ensure
the process is publicly available to all of the workforce. Review annually, or
when significant agency changes occur that could impact this safeguard.
3. Each agency must report all cybersecurity incidents to ITS involving their
information and information systems, whether managed by the state agency,
contractor, or other source. Please refer to the State of MS’s Enterprise
Cybersecurity Incident Reporting Guidelines document for more detailed
information on reporting cybersecurity incidents and timelines. The document
can be found on the ITS website (www.its.ms.gov).
F. Each agency must test the agency incident response capability.
1. Plan and conduct routine incident response exercises and scenarios for key
personnel involved in the incident response process to prepare for responding
to real-world incidents. Exercises need to test communication channels,
decision making, and workflows. Conduct testing on an annual basis, at a
minimum.
G. Each agency must conduct post-incident reviews. Post-incident reviews help prevent
incident recurrence through identifying lessons learned and follow-up action.
1. Document the way the incident was identified, actions taken in response to the
incident, and any impact to agency resources or functionality incurred as a
result of the incident.
2. Lessons learned from post-incident reviews must be documented and
deficiencies must be addressed in a timely fashion. Actions taken to remediate
known identified deficiencies must be documented.
H. ITS recommends that each agency establish and maintain security incident thresholds,
including, at a minimum, differentiating between an incident and an event. A security
event is an observed change to the normal behavior of a system, environment,
process, workflow, or person. Examples of events may include router ACLs were
updated; firewall policy was pushed. An incident is an event that negatively affects
the confidentiality, integrity, and/or availability in a way that impacts the agency.
Examples: attacker posts company credentials online, attacker steals customer credit
card database, worm spreads through network.
1. Review the post-incident process annually, or when significant agency
changes occur that could impact this safeguard.