Incident response playbook for OCSI cybersecurity incidents — aligned with NIST SP 800-61 and DFARS 252.204-7012 72-hour reporting requirement.
This Incident Response Plan establishes procedures for detecting, reporting, containing, eradicating, and recovering from cybersecurity incidents affecting OCSI systems and CUI data. This plan covers all OCSI information systems including the public website, Command Center, and supporting infrastructure.
Key Reference: DFARS 252.204-7012 requires reporting of cyber incidents involving CUI to the DoD Cyber Crime Center (DC3) within 72 hours of discovery.
| Role | Name | Responsibility | Contact |
|---|---|---|---|
| IR Lead / Security Officer | Kit E. Floyd, Jr. | First responder, triage, initial containment, communication coordination | Internal contact list |
| Executive Authority | Sandra O. Floyd | Decision authority for major incidents, external communications, legal/regulatory coordination | Internal contact list |
| External IR Partner | TBD — Not yet engaged | Technical incident response, forensics, evidence preservation, remediation support (external MSSP or equivalent MSSP — engagement pending) | Not yet contracted |
| Business Development | Byron Bey | Client communication, contract impact assessment | Internal contact list |
| Severity | Category | Examples | Response Time | DFARS Report |
|---|---|---|---|---|
| SEV-1 Critical | CUI Compromise | Confirmed data breach, unauthorized CUI access, credential theft affecting CUI systems | Immediate (within 1 hour) | Yes — 72 hours |
| SEV-2 High | Active Attack | Ongoing unauthorized access, account takeover, website defacement | Within 4 hours | If CUI involved |
| SEV-3 Medium | Vulnerability / Attempted Attack | Multiple failed login attempts, suspicious activity in audit log, new vulnerability discovered | Within 24 hours | No (unless escalated) |
| SEV-4 Low | Policy Violation / Anomaly | Single failed login, configuration drift, expired certificate warning | Within 72 hours | No |
sessionStorage.clear() on affected endpoints)node deploy-godaddy.cjsocsi_audit_log from localStorage to JSON file with timestamp in filenamecurl -I https://ocsi.co