Introduction to Business Information Systems – 4 questions

Introduce the concept of incident notification by explaining that a key element of any response plan is to define who to notify and who not to notify in the event of a computer security incident. Review the questions that should be addressed when developing an incident notification process.

1. Within the company, who needs to be notified, and what information does each person need to have?

2. Under what conditions should the company contact major customers and suppliers?

3. How does the company inform them of disruption in business without unnecessarily alarming them?

4. When should local authorities or the FBI be contacted?

