Advisory

Advisory  Incident Response Policy

Date: 01/01/2025
Organization: Cybersecurity and Enterprise Risk Management
Referenced Sources: MGL Chapter 7D, Section 2

The Incident Response Policy establishes the minimum security requirements that must be implemented to protect the Commonwealth’s information assets in the event of a cybersecurity incident, data breach, or other security compromise of the Commonwealth’s information assets.

Contact   for Incident Response Policy

Cybersecurity and Enterprise Risk Management

Online

For cybersecurity or risk management questions: Email Cybersecurity and Enterprise Risk Management at ERM@mass.gov

Table of Contents

Purpose

The purpose of this policy is to establish the minimum security requirements that must be implemented to protect the Commonwealth’s information assets in the event of a cybersecurity incident, data breach, or other security compromise of the Commonwealth’s information assets. This policy reinforces the Commonwealth’s commitment to an effective cyber incident response program, and outlines the framework, principles, and controls required to ensure the protection of the Commonwealth’s information technology environment.

Downloads   for Incident Response Policy

Contact   for Incident Response Policy

Online

For cybersecurity or risk management questions: Email Cybersecurity and Enterprise Risk Management at ERM@mass.gov
Referenced Sources:

Help Us Improve Mass.gov  with your feedback

Please do not include personal or contact information.
Feedback