ministryofjustice / modernisation-platform

A place for the core work of the Modernisation Platform • This repository is defined and managed in Terraform
https://user-guide.modernisation-platform.service.justice.gov.uk
MIT License
680 stars 290 forks source link

NCSC - Validate/update our runbooks to cover how to handle security incident alerts #7551

Closed SimonPPledger closed 1 week ago

SimonPPledger commented 1 month ago

User Story

Following on from the review by NCSC, we need to know what to do in the case of a security incident, including:

Value / Purpose

This helps to minimise impact of any security threats by enabling us to respond quickly

Useful Contacts

No response

Additional Information

No response

Definition of Done

ep-93 commented 3 weeks ago

Incident runbook is here - https://user-guide.modernisation-platform.service.justice.gov.uk/runbooks/manage-an-incident.html#incident-process

Will update

ep-93 commented 3 weeks ago

how to potentially revoke IAM and network access -

IAM - https://user-guide.modernisation-platform.service.justice.gov.uk/runbooks/revoking-user-access.html

Network - https://user-guide.modernisation-platform.service.justice.gov.uk/runbooks/revoke-network-access.html

how and what we communicate - https://user-guide.modernisation-platform.service.justice.gov.uk/runbooks/manage-an-incident.html

where we raise any subsequent ticket - I have added links to mod platform security repo incident raising, and raised a test issue as asked.

ep-93 commented 3 weeks ago

Test issue raised - https://github.com/ministryofjustice/modernisation-platform-security/issues/21

mikereiddigital commented 2 weeks ago

No team review has been undertaken but this can be organised separately. I will raise a follow-on ticket to cover this as @ep-93 is away on leave.