Skip to main content

Personal tools

Translate

PG26 Information Security (IS) Incidents Response Plan

PG26 Information Security (IS) Incidents Response Plan

  1. Purpose
    The purpose of this directive is to establish procedures to ensure efficient and effective management and response to Information Security (IS) incidents.
  2. Scope
    This directive applies to all APS employees, staff, students, and third parties or subcontractors using or accessing APS information or any physical or technological infrastructure. Any agreements with vendors will contain language similar to that which protects the agency.

    This plan specifies the procedure to identify, contain, escalate, and notify the incident; collect evidence and conduct forensic analysis; eradicate root cause, and learn and improve from IS incidents.
  3. Incident Response Plan Procedure
    Information Security incidents are events or security threats that impact or have the potential to impact the confidentiality, availability, or integrity of APS’ information and support assets. This comprises technological, physical, environmental, administrative, and any other event or suspicious activity, intentional or unintentional, that can compromise APS’ information and its support assets.

    Some examples include: unauthorized access or break-in to physical infrastructure or areas that store APS’ critical information or resources, loss or theft of information (digital files or paper documents) or devices, unintentional disclosure of confidential information (human error), unauthorized devices connected to the network, natural disasters affecting physical infrastructure, network tampering or manipulation, malware outbreaks, power outages causing data loss, unauthorized login attempts to any device; among others.

    3.1 Identification of IS Incidents
    All APS employees, staff, students, and interns must immediately report all observed or suspected IS events, incidents, breaches, vulnerabilities, or weaknesses to the APS’ IT helpdesk at (505) 830-8080 or infosec@aps.edu.

    Service Desk
    The Information Security Department will assess and categorize the event as follows:

    - Verify the information provided by the user and find out more details to determine if the event qualifies as an incident or as a false alarm.
    - Assign the ownership of the incident or potential incident.
    - Identify and establish a chain of custody if potential evidence needs to be preserved or handled
    - Determine the severity of the incident and escalate it as necessary.

    3.2 Confirmed IS Incident Management
    If an incident or potential incident is identified or confirmed, the response process to address, contain, and resolve or mitigate the incident must be initiated as follows:

    - All access to the information or support assets that might be compromised shall be removed, and a chain of custody shall be established if potential evidence is handled.
    - The APS incident response team (IRT) to contain or handle the breach or exposure shall be established. The IRT shall be led by the Chief Information Security Officer (CISO) or the Chief Technology Information and Strategy Officer if the CISO is not available. The IRT shall include the following people:

    - Deputy Superintendent of Operations
    - Chief Technology Officer
    - Executive Director, Technology of IT Infrastructure and Operations
    - Executive Director of Educational Resources
    - Chief of Human Resources and Legal Support Services
    - Chief Communications Officer
    - Additional individuals as deemed necessary by the CISO

    The APS IRT, along with the designated forensic team, shall analyze the IS incident or potential incident to analyze the incident and agree on the required actions, evaluate the risks of these actions, and define and deploy the containment measures.

    The APS Superintendent shall be notified of the IS incident and the agreed actions.

    3.2.1 Forensic Analysis

    APS cyber insurance will include access to forensic investigators and experts, and the APS IRT and forensic investigators shall determine how the incident or breach occurred; the types of data involved; the number of internal/external individuals and/or organizations impacted; and analyze the incident or breach to determine the root cause to eradicate it, if possible. Forensic investigators will also advise APS on how to establish the chain of custody, to collect the evidence, and preserve the proof, if required.

    APS IRT and forensic investigations must agree to the required actions, evaluate the risks of these actions and define and deploy the containment measures. All this response plan must be coordinated with any other existing plans at APS and external authorities or interested parties, if required.

    3.2.2 Communication plan
    The Communication Department and the CISO will determine how to communicate the breach to: a) internal employees, b) the public, and c) those directly affected according to the APS’ communication protocols established, and also if to invoke crisis management.

    3.3 Notification of IS Incident
    APS shall provide notification to each individual or third party who has been affected or subject to the security incident or breach. Notifications shall be made in the most expedient way possible, within 24 hours of discovering the security incident or breach if any employee or student’s PII or cardholder data is compromised, and no later than 45 calendar days for any other affected individual or third party.

    3.3.1 Notification Methods
    APS shall provide IS incident notification as required by: a) United States mail 2) Electronic notification 3) Substitute notification as necessary. Notification method determination shall consider the affected individual’s safety.

    Notification content
    APS shall include, but not be limited to: incident description, date and time, type of information compromised, steps being taken to contain and mitigate the incident or breach, contact information, applicable security recommendations, and signature of the APS’ authorized representative.

    3.3.2 Notification to NM Attorney General and Credit Reporting Agencies
    If more than 1,000 New Mexico residents are affected by a single security breach, APS shall notify the New Mexico Attorney General’s Office within 30 days of the breach, providing the information about the incident as it is defined in item 3.3.1 as Notification content of this procedural directive. Additionally, APS will post a notification of the incident on the APS website.

    3.4 Lessons Learned
    Lessons learned shall be documented to identify what could have been done better and include it into a plan to enhance the IS incident management.

    3.5 Contracts with Third Party
    APS shall require that all third-party or subcontractor(s) that have a contractual relationship with APS must implement and maintain a security response plan in place in addition to security policies and procedures to ensure the appropriate protection of APS’ information and resources.

    Additionally, third parties shall collaborate if a security breach happens with any required information about the incident, cooperate with investigations or forensic analysis, take steps to contain or mitigate the incident, and collaborate to develop an incident response and remediation plan, among others.

    3.6 Roles and Responsibilities
    - Chief Information Security Officer (CISO) or appropriate designee shall lead and establish the APS IRT. Additionally, CISO must coordinate and ensure effective incident response and resolution.
    - Chief of the Human Resources and Legal Support Department shall provide advice on any legal implications and requirements.
    - APS employees, staff, students, interns, and third parties shall immediately report all observed or suspected IS events, incidents, breaches, vulnerabilities or weaknesses in accordance with this procedural directive. They shall not perform any action to eradicate or contain the incident unless explicitly instructed by the APS IRT and shall not disclose information relevant to the incident to unauthorized entities.
  4. Enforcement
    Any APS employee, staff member, or intern found in violation of this procedural directive may be subject to disciplinary action, up to and including termination of employment or internship. Any third-party partner company found in violation may face legal consequences, up to termination of the contract.


Administrative Position:

  • Deputy Superintendent of Operations

Department Director:

  • Chief of Technology
  • Chief Information Security Officer

Procedural Directive Cross Ref.:


NSBA/NEPN Classification: GBA1
Adopted: May 5, 2026