资安事件处理作业办法.docx
《资安事件处理作业办法.docx》由会员分享,可在线阅读,更多相关《资安事件处理作业办法.docx(9页珍藏版)》请在淘文阁 - 分享文档赚钱的网站上搜索。
1、Revision HistoryProcedure:T/f/e.nTreating Method of the Info-Security Affairs|資安事件處理作業辦法|Rev:Rev.ECNDateOriginatorReasonA2006/6/22Yoyo YuanInitial ReleaseIssue stampDateTRADE SECRETS, CONFIDENTIAL INFORMA TION, PROPRIETARY INFORMATION NOTICE and COPYRIGHTThe Copyright in this document is vested in A
2、ltus Technology Inc. The document may not be reproduced in whole or in part, or stored in a retrieval system, or transmitted in any form or by any means electronic, mechanical, photocopying or otherwise, without the prior written per-mission of Altus Technology Inc. This document3 or its contents, c
3、ither in whole or in part, must not be communicated to the press or any person not authorized to receive it. The data shall not be duplicated, used, or disclosed in whole or in part for any purpose other than to evaluate the contents. This restriction does not limit the right of the recipient to use
4、 information contained in this data for its review and use for its intended purpose. The data subject to this restriction is contained in pages of this document marked Altus Proprietary DataContentsProcedure:1Title:1Rev:1A1Contents2Treating Method of the Info-Security Affairs31.0 Purpose 目 的32.0 Sco
5、pe適用範圍33.0 Role and Responsibility 角色與職貝34.0 Emergency work flow chart of Info-Security Affairs 資安事件應變作業流程圖.55.0 Reporting of Info-Security Affairs 通報作業56.0 Disposition of Info-Security Affairs 處理作業67.0 Improving of Info-Security Affairs 改善作業78.0 Audii 稽核79.0 Encourage for Disclosure 舉報獎勵710.0 Input
6、 and Export 輸入輸出811.0 Appendices and Attachments 附件9Treatinq Method of the lnfo-Securitv Affairs1.0 Purpose 目的Standardize the handling mechanism of the Info-Security affairs, improve the treatment quality of the incident. The relevant affairs of making the InfoSecurity affairs notify , dealing with
7、, improving , auditting etc. are accorded with to some extent.規范資訊安全事件處置機制,提升事件的處理品質,使資訊安全事件通報、處理、 改善、稽核等相關事務有所依據。2.0 Scope適用範圍2.1 This treating method applies to Foxconn Electronics Inc. Info-Security affairs contingency to disposition.本作業辦法適用於富士康科技集團資訊安全事件應變處置作業。3.0 Role and ResponsibiHty 角色與職責3.1
8、 The table of role and responsibility 角色與職責覽表Department部門Role 角色Responsibility 職責資安管理部資安主管a審核資安事件處理計劃b對資安案件分級判斷c建置資安措施,執行資安監控d指導資安處理計劃執行e依計上級指導修訂處理計劃f管控是否需要協作單位支援緊急應變處理小組a規劃危機處理計劃程式b協助事件發生單位査明安全事件原因c協調執行緊急應變措施d執行資安稽核e協助事發單位執行改善作業f撰寫結案報告記錄人員a事件受理、通報b根據客服系統做過程跟綜 c整理資安件結案文檔舉報者a自願向資安管理部舉報資安事件 b必要時進行指證協作
9、單位事件發生單位a及時通報事件b主導組建事件處理小組事件處理小組a制訂處理、改善詳細計劃;b執行計劃並提出事件處理報告;Department部門Role 角色Responsibility 職責協作單位集團資訊安全 委員會a接受資安事件通報,制訂處理計劃:b指導審核處理小組之作業:c指導危機預防演練資安事件應急 專家組a處理重大資安事件b訓練緊急應變處理小組,事件處 理小組安全技術c隊集團安全策略提出建議和意見CIO資安事件主任 委員a下達重大資安事件處理指示 b對重大資安事件處理計劃審核c啟動災難復原機制3.2 Affairs Disposition Group事件處理小組3.2.1 Can
10、be units leading factor happen by the incident and set up in Affairs Disposition Group, the incident happens unit, incident relevant unit, InfoSecurity Management (in case of necessity ) transfer manpower to make up , may include the professional service provider of outside.事件處理小組可由事件發生單位主導組建,事件發生單位
11、、事件相關單位、資安管理 部(必要時)抽調人力組成,可能包括外部專業服務提供商;3.2.2 Affairs Disposition Group should work under the guidance of Info-Security Committee, Local Information Department Manager and Administrative Executive, and report to them.事件處理小組應在資安委員會、本部門資訊主管、行政主管指導下工作並且向資安事 件處理委員會、本部門資訊主管、行政主管報告;3.3 Info-Security Commi
12、ttee of the Group集團資安委員會3.3.1 Info-Security Committee of the Group is organized by Central Information Department Manager, Group Information Department Manager and senior information technical staff.集團資安委員會乃召集性組織,成員由各事業群/中央周邊單位資訊主管,資深資訊技 術人員組成;3.3.2 Advisor group members is organized by senior admin
13、istrative executive, IT Manager, technical staff or senior personages of outside manufacturer, professional service organization.顧問組成員可由集團內部資深行政主管、IT主管、 技術人員或者外部廠商、專業服務 機構的資深人士擔任;3.3.3 If Info-Security Affairs is happened, according to incident nature, involve the professional field, deal with the c
14、ommittee to transfer relevant personnel from the incident, instruct Info-Security Affairs Disposition Group promotes ones work.如遇資安事件發生,則根據事件性質、涉及專業領域,從事件處理委員會抽調相關人 員,指導資安事件處理小組開展工作;4.0 Emergency work flow chart of Info-Security Affairs資安事件應變作業流程圖處理重大資安事件緊急應變處理小組、事件處理小組安全技術對集團安全策略提出建議 和意見5.0 Reporti
15、ng of Info-Security Affairs 通報作業5.1 Hot Line & E-mail for Info-Security Affairs notify (report).資安事件通報熱綫、信箱。5.1.1 Hot Line for Info-Security Affairs notify (report):560-102, nder the care of Product Dynamic Solution Services Info-Security Management.集團設置資安事件通報(舉報)熱綫:560-102,由管資訊資安管理部負責;5.1.2 Can als
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- 事件 处理 作业 办法
限制150内