Categories: Government

Securities Exchange Commission (SEC) “Incident Response Capability Handbook” – April 2014

Background

Although the purpose and scope of this document is exempt from disclosure, I was able to find reference to the handbook to obtain a description of it, and get an idea of it’s purpose.

The following comes from the 2010 Annual FISMA Executive Summary Report:

The SEC has implemented policies and procedures to address Incident Response which are well documented and address the NIST and OMB43 guidance. C5i’s review of the SEC’s Incident Response Capability (IRC) Handbook provided evidence of the SEC’s attributes for its incident response and reporting program. The SEC IRC Handbook was developed to assist in the mission of the SEC Computer Security Incident Response Team. The handbook defines processes and procedures, roles and responsibilities, types of incidents, reporting criteria and timeframes, evidence collection and handling, event categories and incident severity, etc., as well as post-mortem procedures, e.g., lessons learned. The handbook also defines which types of incidents are required to be reported to the United States Computer Emergency Readiness Team (US-CERT) (based on OMB A-130 and FISMA) and which do not. The types of incidents that are not required to be reported are incidents that are self-inflicted, did not result in unauthorized access, or were not a result of attackers’ actions.

Continue scrolling for more...

Document Archive

 Securities Exchange Commission (SEC) “Incident Response Capability Handbook” – April 2014 [46 Pages, 2.2MB]

https://documents.theblackvault.com/documents/SEC/SEC-IRS-April2014.pdf

Follow The Black Vault on Social Media:

This post was published on April 12, 2017 8:30 pm

John Greenewald

Recent Posts

The DoD Inspector General’s Evaluation of the DoD’s Actions Regarding Unidentified Aerial Phenomena

This article was originally written in August 2024. However, additional document releases related to these…

July 15, 2025

Do Not Respond: Pentagon Staff Instructed to Ignore The Black Vault’s UAP Inquiry

The Department of Defense (DoD) has released 151 pages of internal records related to the…

July 15, 2025

U.S. Government Confirms Multiple Drone Incursions Over Pantex Nuclear Facility; Newly Released Documents Reveal Previously Unreported Security Events

The U.S. Department of Energy (DOE) has released a series of previously undisclosed documents confirming…

July 12, 2025

Air Force Confirms Drone Swarms Over Wright-Patterson AFB Led to Airspace Shutdown; Videos and Reports Released

Newly released Air Force records confirm that Wright-Patterson Air Force Base (WPAFB) in Ohio experienced…

July 11, 2025

Navy Withheld Nearly 500 Pages About UAP Video Release Decision, Records Show FOIA Pressure Drove Disclosure

Newly released documents obtained through the Freedom of Information Act (FOIA) reveal that the U.S.…

July 9, 2025

CIA Mishandles UFO Files Again: Intelligence on Soviet UFO Reports Lost Forever

The CIA’s history of losing or mismanaging UFO-related records continues with yet another example, this…

July 7, 2025