Published on : 16 Jan , 2018
Introduction
Cyber security incident is a crisis scenario that every organization is vulnerable to,
which makes it one of the most important types of high-risk scenarios to include within your crisis preparedness program.
Cyber Crisis Management Plan (CCMP) is the document which helps organisation in handling such scenarios.
Specific Sections to be Included during Preparation of Cyber Crisis Management Plan (CCMP) for CII
Organisation while formulating CCMP may include following section during preparation of CCMP for Critical Information Infrastructure (CII).
-
While preparing CCMP in an organisation, consideration of CII component should be viewed in holistically with all relevant stake holders.
E.g. Third party organisation, inter / intra organisational dependencies and functional dependencies etc.
-
For operational requirements organization require sharing CCMP document with third party organisation / System Integrator / Vendors etc.,
hence proper classification of the document is required. Sharing of sensitive information like detailed IP addresses, network equipment details,
configuration details etc should be avoided for CII components and as far as possible defined in broader terms.
-
Specific portion in the document should clearly mention sharing of cyber incidence with NCIIPC for CII/Protected Systems.
Notifying the incidents spanning in multiple states and national level would help avert critical services to be hit during the incident.
-
It is suggested to include NCIIPC control guidelines ver2.0 (or any further updates from time to time) as reference document applicable for CII systems in CCMP.
-
Incorporate NCIIPC contact details in CCMP document for ready reference.
-
CCMP mock drill plan for CII components should be defined separately and with minimum timeframe as per the organisational Information security policy.
-
CII organizations may forward CCMP documents to NCIIPC for consultation.
This will help in close coordination between NCIIPC and CII organization in protecting critical national assets.