Policy Advisory

Policy Advisory  Information Security Incident Management Standard

Date: 01/01/2025
Organization: Cybersecurity and Enterprise Risk Management
Referenced Sources: MGL Chapter 7D, Section 2

The Information Security Incident Management Standard reinforces the Commonwealth’s commitment to an incident management strategy and outlines the controls necessary to safeguard the Commonwealth’s information assets and reduce risks.

Contact

Cybersecurity and Enterprise Risk Management

Online

For cybersecurity or risk management questions: Email Cybersecurity and Enterprise Risk Management at ERM@mass.gov

Table of Contents

Purpose

This standard documents the requirements for managing an information security incident; describes the actions to be taken should an incident occur; and details each phase of the incident management life cycle, including identification, investigation, response, and remediation.

Downloads

Contact

Online

For cybersecurity or risk management questions: Email Cybersecurity and Enterprise Risk Management at ERM@mass.gov
Referenced Sources:

Help Us Improve Mass.gov  with your feedback

Please do not include personal or contact information.
Feedback