The definition of a security breach or incident includes the following: - Unauthorised access attempts (hacking);
- Unauthorised network and port scanning;
- Denial of Service (DOS) attacks;
- Website defacement;
- Theft, misuse or critical loss of IT resources including equipment, system information or login identities/passwords;
- Work practices that do not comply with security policy or accepted codes of practice;
- Unmanaged Viruses, Worms or Malicious Code;
- Other related suspicious activity, event or situation.
The information needed to report a security breach includes: - General nature of the security incident;
- Systems involved in the incident;
- Impact or potential/impact of the incident;
- When the security incident occurred;
- Details of person/s involved in the incident;
- How the security incident occurred;
- Possible preventative measures for control.
Security breaches can be reported by: emailing infosec@scu.edu.au or calling (02) 6620 3290. Download IT Security Incident Management Policy
Updated: 02 February 2009 |