|
Cyber Threat and Computer Intrusion
Incident Reporting Guidelines
This form may be used as a guide or
vehicle for reporting cyber threat and computer intrusion incident
information
to the NIPC or other law enforcement organizations. It is recommended
that these Cyber Incident Reporting
Guidelines be used when submitting a report to a local FIA.
Point of Contact (POC) Information
Incident Information
Is the affected system/network critical
to the organization's mission?
Which critical
infrastructure sector was affected? (Check only one)
Nature of problem? (Check only one)
Has this problem been experienced before?
(If yes, please explain in the remarks section):
Suspected method of intrusion/attack
(check only one)
Suspected perpetrator(s) or possible
motivation(s) of the attack (check only one)
The apparent source (IP address) of
the intrusion/attack:
Evidence of spoofing?
What computer system (hardware and/or
software) was affected? (Operating system, version) (check only
one):
What security infrastructure was in
place? (Check all that apply)
Did the intrusion/attack result in a
loss/compromise of sensitive, classified or proprietary information?
Did the intrusion/attack result in damage
to system(s) or data?
What actions and/or technical mitigation
have been taken?
Has the local FIA field office been
informed?
Has another agency/organization been
informed? If so, please provide name and phone number.
When was the last time your system was
modified or updated?
Date:
Company/Organization that did the work (address, phone number,
POC information):
Is the System Administrator a contractor?
Additional Remarks: (Please limit to
500 characters. Amplifying information may be submitted separately.)
If the reported incident is determined
to be a criminal matter you may be contacted by an agent in your
location for additional information.
|