Security Policies Incident Response Plans

Lack of Cybersecurity Awareness programs to the Employees, Lecturer and Students. 

Risk Description

Untrained Employee, Lecturer and Students may use weak or common or more likely to fall for deceptive emails, message, or social engineering, download malicious software through unsafe link.  

Existing Controls

Traditional Antivirus  

Risk Mitigation Policy

1. Implement Cybersecurity Awareness for the Employee, Lecturer and Students.  
2. Implement Complex password policy.  
3. Implement Access control policy  
4. Monitor Employee, Lecturer and Students activities using SIEM.  
5. Install the Endpoint Detection and Response (EDR) System. 

Location/Contact Person details

The chairman of risk management sub-committee in UTAS-SUR
Dr.Sami Al-Batashi, Phone: +968 9293 9604
Email: sami.albattashi@utas.edu.om

Risk Management Authority

Risk Management Committee in UTAS-SUR

Risk Likelihood

Medium

Risk Impact

High

Risk Level

Medium

Risk Incident Response Procedures

  1. Identify problems caused by lack of awareness. 
  2. Evaluate damage and isolate the target device or system from the network. 
  3. Find a solution and analyze the problem and error. 
  4. Document the problem and its resolution on the device or system. 
  5. Restore the state to its pre-problem state. 

Risk Termination

  1. By sending the final report explaining the problem causes and how we can mitigate next time.  
  2. Modified the awareness program.