Menu
Login
  • Home
  • SevernSide IUC
  • Practice Services
  • Staff Resources
  • Home
  • SevernSide IUC
  • Practice Services
  • Staff Resources
home/Knowledge Base/Policies & SOPs/Cyber and Data Security Incident Response Plan
Popular Search:Policies, Training, Staff Newsletter

Cyber and Data Security Incident Response Plan

BrisDoc Governance Team

Purpose and Scope

This plan provides practical guidelines on responding to cyber-attacks and data breach incidents in a consistent and effective manner. The plan establishes a team of first responders to an incident with defined roles, responsibilities, and means of communication.

This response plan sets out specific provisions for a cyber or data incident and is in addition to the deployment of the Major or Critical Incident Policy which may also be enacted during such an event.

Goals for Cyber Incident Response

When a cyber security incident occurs, timely and thorough action to manage the impact of the incident is critical to an effective response process. The response should mitigate damage through clear, coordinated actions. Specifically, the response goals are:

  • Preserve and protect the confidentiality of patient, co-owner and business information and ensure the integrity and availability of BrisDoc systems, networks, and related data.
  • Help BrisDoc personnel recover their business processes after a computer or network security incident or other type of data breach.
  • Provide a consistent response strategy to system and network threats that put BrisDoc data and systems at risk.
  • Develop and activate a communications plan including initial reporting of the incident as well as ongoing communications, as necessary.
  • Address cyber related legal issues.
  • Coordinate efforts with external support teams.
  • Minimize BrisDoc’s reputational risk.
  • Engage third-party stakeholders where necessary.
  • Monitor evolving cyber threats

Incident Response Team (IRT)

A team comprised of BrisDoc staff, advisors, and service providers shall be responsible for coordinating incident responses and known as the Incident Response Team (IRT).  The IRT shall consist of the individuals listed in Appendix A, having the noted roles and responsibilities.

This team will have both primary members and secondary members.  Secondary members will be become involved dependent on the incident. In the event of a cyber-attack CFC, Defense.com and Sophos will be informed as a matter of course. The primary members of the IRT will act as first responders to an incident that warrants IRT involvement, according to the incident’s severity.  The entire IRT would be informed and involved in the most severe incidents.

IRT members may take on additional roles during an incident, as needed.  Contact information, including a primary and secondary email address, plus office and mobile telephone numbers shall be maintained and circulated to the team.  The IRT will draw upon additional staff, consultants, or other resources, (often referred to as Subject Matter Experts – SME’s) as needed, for the analysis, remediation, and recovery processes of an incident.  The Digital function plays a significant role in the technical details that may be involved in an incident detection and response and can be considered an SME in that regard.

There shall be a member of the IRT designated as the Incident Response Manager (IRM), who will take on organisational and coordination roles of the IRT during an incident where the IRT is activated for response to the incident.

Attached Files
#
File Type
File Size
Download
1 .pdf 358.92 KB Cyber and Data Security Incident Response Plan V2
Related Articles
  • VAT Policy
  • HHS Addictions
  • IG Information Risk
  • BrisDoc Safeguarding Training SOP
  • BrisDoc Information/Subject Access Request
  • BrisDoc Digital Acceptable Use Policy

Can't find what you're looking for? Contact Us

Categories
  • Information Governance
  • IUC Rotas
    • 1. Rota – Monday
    • 2. Rota – Tuesday
    • 3. Rota – Wednesday
    • 4. Rota – Thursday
    • 5. Rota – Friday
    • 6. Rota – Saturday
    • 7. Rota – Sunday
  • Policies & SOPs
  • Practice Services
    • BMC
    • CKMP
    • HHS
    • PCN
  • SevernSide IUC
    • Bases / Urgent Treatment Centres
      • 168 Medical – Weston Base Documents
      • Christchurch Base Documents
      • Clevedon Base Documents
      • Cossham Base Documents
      • Greenway Base Documents
      • Marksbury Road Base Documents
      • Osprey Court Control Room Documents
    • IUC Business Continuity – Disaster Recovery
    • IUC Roles
      • Call Handlers – IUC
      • Drivers – IUC
      • Hosts – IUC
      • On Call Managers – IUC
      • Shift Managers – IUC
      • WaCCs – IUC
        • Meeting minutes – April 2022
    • Mental Health IAP
      • IAP Call Handlers
      • IAP Shift Manager
      • IAP SOPs
    • SESUI
    • System CAS
  • Staff Resources
    • Co-owners Council Documents
      • Co-owners Council Minutes
    • Handbooks
    • Induction Documents
    • New Starter Checklists
    • Parental Leave Forms
    • Training
    • Useful Forms
  • User Guides
    • RotaMaster Admin Documents
  • Wellbeing Leads

  Case Streaming From NHS 111 & CCAS Contingency.

Data Protection  

All Rights Reserved | BrisDoc Healthcare Services
Popular Search:Policies, Training, Staff Newsletter