Florida Administrative Code
60 - DEPARTMENT OF MANAGEMENT SERVICES
60GG - Florida Digital Service
Chapter 60GG-2 - STATE OF FLORIDA CYBERSECURITY STANDARDS
Section 60GG-2.005 - Respond
Current through Reg. 50, No. 187; September 24, 2024
The respond function of the SFCS is visually represented as such:
Function |
Category |
Subcategory |
Respond (RS) |
Response Planning (RP) |
RS.RP-1: Execute response plan during or after an Incident |
Communications (CO) |
RS.CO-1: Ensure that personnel know their roles and order of operations when a response is needed |
|
RS.CO-2: Report Incidents consistent with established criteria |
||
RS.CO-3: Share information consistent with response plans |
||
RS.CO-4: Coordinate with Stakeholders consistent with response plans |
||
RS.CO-5: Engage in voluntary information sharing with external Stakeholders to achieve broader cybersecurity situational awareness |
||
Analysis (AN) |
RS.AN-1: Investigate notifications from detection systems |
|
RS.AN-2: Understand the impact of Incidents |
||
RS.AN-3: Perform forensic analysis |
||
RS.AN-4: Categorize Incidents consistent with response plans |
||
RS.AN-5: Establish processes to receive, analyze, and respond to vulnerabilities disclosed to the Agency from internal and external sources |
||
Mitigation (MI) |
RS.MI-1: Contain Incidents |
|
RS.MI-2: Mitigate Incidents |
||
RS.MI-3: Mitigate newly identified vulnerabilities or document accepted risks |
||
Improvements (IM) |
RS.IM-1: Incorporate lessons learned in response plans |
|
RS.IM-2: Periodically update response strategies |
(1) Response Planning. Each Agency shall establish and maintain response processes and procedures and validate execution capability to ensure Agency response for detected Cybersecurity Incidents. Each Agency shall execute a response plan during or after an Incident (RS.RP-1).
(2) Communications. Each Agency shall coordinate response activities with internal and external Stakeholders, as appropriate, to include external support from law enforcement Agencies. Each Agency shall:
(3) Analysis. Each Agency shall conduct analysis to adequately respond and support recovery activities. Related activities include:
(4) Mitigation. Each Agency shall perform Incident mitigation activities. The objective of Incident mitigation activities shall be to attempt to contain and prevent recurrence of Incidents (RS.MI-1); mitigate Incident effects and resolve the Incident (RS.MI-2); and address vulnerabilities or document as accepted risks.
(5) Improvements. Each Agency shall improve organizational response activities by incorporating lessons learned from current and previous detection/response activities into response plans (RS.IM-1). Agencies shall update response strategies in accordance with Agency-established policy (RS.IM-2).
Rulemaking Authority 282.318(11) FS. Law Implemented 282.318(3) FS.
New 3-10-16, Amended 1-2-19, Formerly 74-2.005, Amended 9-18-22.