SECURITY DOCUMENT TEMPLATE FOR PROCEDURES



Sample Statement/ Attestation Letter

To: K. Mig Hofmann, Information Security Officer, mig@sfsu.edu

Cc: Immediate Supervisor, Dean or Department Head

Re: Description of computing or information security incident

_______________

• Description of event including time, date, circumstance.

• Assessment of the personal or sensitive data potentially lost, stolen or accessed. (Attach a copy if possible.) Indicate how many possible records or details about a database, if known.

• Categorize the type of information according to the new classifications (below) established by the CSU:

Please visit the website for details on CSU data classification:

• Include information on the potential number of individuals impacted and all names and contact information (if known.)

• Detail any mitigating protections in place to reduce the probability of unauthorized access or exemption from disclosure requirements. For instance, if the data was encrypted, please indicate the algorithm and implementation practice and reason you think no unauthorized access was ever successfully achieved.

• Names and contact information of individuals able to support this report and/or provide additional detail if needed in an investigation.

• Any other additional information you feel is relevant.

I attest that the above information is supplied to the best of my knowledge and ability.

Name, signature, date

................
................

In order to avoid copyright disputes, this page is only a partial summary.

Google Online Preview   Download