Commit 9199e012 authored by Mitra Jozenazemian's avatar Mitra Jozenazemian
Browse files

Update file security-incident-communication-plan.md

parent 7ae1ac89
Loading
Loading
Loading
Loading
+4 −4
Original line number Diff line number Diff line
@@ -74,7 +74,7 @@ As security practitioners and incident response engineers, our security assuranc
- Acting as an approval point on final messaging to ensure it's ready for external use
- Liaising with PR and corporate communications for additional reviews and/or messaging needs (public/media statements)
- Deploying the messaging via collaboration with our PR (media statement), Content Marketing (blog post) and Marketing Operations teams (email response)
- Posting final communications materials to slack channels (`#developer-relations`, `#social_media_action`, `#sales`, `#security_discuss` and `#customer-success`) for awareness and use.
- Posting final communications materials to slack channels (`#social_media_action`, `#sales`, `#security_discuss` and `#customer-success`) for awareness and use, and pinging `@devrel` for Developer Relations awareness.
  - `Support manager on call` will manage support team awareness

## Extended team roles, responsibilities and points of contact
@@ -82,9 +82,9 @@ As security practitioners and incident response engineers, our security assuranc
- **Marketing Operations:** Responsible for sending incident-related email to impacted parties in a security incident.  This group has established a [Marketing emergency response process](/handbook/marketing/emergency-response/#marketing-emergency-response) and is engaged by [creating an incident communication request](https://gitlab.com/gitlab-com/marketing/marketing-operations/-/issues/new?issuable_template=incident_communications) using the `incident_communications` template, tagging in the assigned timezone's `coverage owner` and posting the issue in the #mktgops channel in Slack.
  - Marketing Ops can send emails through MailGun or Marketo. This group will determine based on the information provided what the best platform is for distribution. If a custom distribution list needs to be created, the data team may need to be involved.

- **Support Team:** Using background information and prepared responses provided by the Security Engineer On Call and Communications Manager On Call, our Support Team will triage and respond to customer communications stemming from the security incident. Contact the on-call manager via `#support_leadership` in Slack. If it's urgent [page the `Support Manager On-call`](/handbook/support/on-call/#engaging-the-on-call-manager) using `/pd-support-manager` command in Slack. To ensure this group has early awareness on security incidents and events they are autotagged as an FYI in the security-external-incident-or-event-response template.
- **Support Team:** Using background information and prepared responses provided by the Security Engineer On Call and Communications Manager On Call, our Support Team will triage and respond to customer communications stemming from the security incident. Contact the on-call manager via `#support_leadership` in Slack. If it's urgent, [page the `Support Manager On-call`](/handbook/support/on-call/#engaging-the-on-call-manager) by triggering a PagerDuty alert: navigate to `#support_leadership` in Slack, type `/pd trigger`, write a summary in the Title field, select **Support Managers** from the list of Impacted Services, and click Create. To ensure this group has early awareness on security incidents and events they are autotagged as an FYI in the security-external-incident-or-event-response template.

- **Developer Relations:** May need to respond to customers and the general public via social channels, as such should be engaged before public-facing materials are released. Any prepared responses or FAQs should be provided to assist with their interactions. Contact this group in `#developer-relations` or any Slack channel by pinging `@devrel`. To ensure this group has early awareness on security incidents and events they are autotagged as an FYI in the `security-external-incident-or-event-response` template.
- **Developer Relations:** May need to respond to customers and the general public via social channels, as such should be engaged before public-facing materials are released. Any prepared responses or FAQs should be provided to assist with their interactions. Contact this group by pinging `@devrel` in any Slack channel. To ensure this group has early awareness on security incidents and events they are autotagged as an FYI in the `security-external-incident-or-event-response` template.

- **Designated Approvers:** This is the group of individuals who act as reviewers and approvers across each piece of communications developed for a security incident. It includes representatives from Security, Support, Customer Success, Legal, Corporate Communications and Investor Relations.

@@ -197,7 +197,7 @@ The communications channels and forms that should be used in an incident or even
- Our most common form of customer response is via direct email communications to affected customers.
- When a deeper dive response is needed, or to ensure broader coverage on a security incident or event, a blog post may be developed on an urgent basis.
- See [deeper dive explanations on forms and channels](/handbook/security/security-operations/sirt/security-incident-communication-plan/#potential-channels-for-use-in-a-security-incident) for consideration
- Communication to [JiHu](/handbook/finance/jihu-support/) should happen via the [#security-vulnerability](https://gitlab-jh.slack.com/archives/C039R937PAN) channel within the JiHu Slack workspace. GitLab team members Dominic Couture, James Ritchey, Jerome Ng, Mek Stittri and Kevin Chu have access to this channel.
- Communication to [JiHu](/handbook/finance/jihu-support/) should happen via the [#security-vulnerability](https://gitlab-jh.slack.com/archives/C039R937PAN) channel within the JiHu Slack workspace.

## Helpful templates and runbooks