Attachment-G5-ACF_Incident Response Plan_V1.0.docx
DOCX document 134 KB Posted
- Attached to
- Legal Services for Unaccompanied Alien Children (UAC) Federal contract opportunity
- Solicitation number
- 75P00126R00003
- Issued by
- Not on record
About this file
This is an Incident Response Plan document for ACF (Administration for Children and Families) systems that outlines procedures, roles, and responsibilities for identifying, reporting, and managing security and privacy incidents.
The plan establishes a structured incident response framework requiring all system users to report suspected security events to their supervisors and the ACF Incident Response Team (IRT) at ACF_IRT@acf.hhs.gov. Upon receipt, the IRT Incident Coordinator creates a ticket in HHS Archer and automatically initiates either a Data Breach incident (if Personally Identifiable Information is involved) or an IT Security incident (if PII is not involved), with notifications sent to relevant Privacy and Security Operations teams. The plan defines incident prioritization using impact and urgency matrices, establishing four priority levels (PO, P1, P2, P3) with corresponding response times ranging from 4 to 24 hours and resolution times ranging from 16 to 72 hours. Key organizational roles include the ACF Chief Information Officer, Chief Information Security Officer, Senior Official for Privacy, System Owner, and various operational teams from the Office of the Chief Information Officer (OCIO). The plan specifies that vendors must request the CSIRC Security Incident Report form by emailing the IRT, and establishes mandatory notification requirements for external hosting personnel and organizations managing ACF data, requiring notification within one hour of discovering any suspected or confirmed incidents. Contact information tables and detailed role responsibilities are provided in appendices, though specific individual names and phone numbers are noted as requiring completion.
View the file
Other files for this federal contract opportunity
Show all 50
Legal Services for Unaccompanied Alien Children (UAC) has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Enter System Name ACF
Incident Response Plan Enter System Name
Version 1.0 Dated: 6/26/25
Table of Contents
| 1. Introduction and Purpose | 3 |
| 2. Incident Response Notifications and Procedures | 3 |
| 2.1 User Reporting of Security Incident | 3 |
| 2.2 ACF Incident Response Team (IRT) Procedures and Reporting | 4 |
| 2.3 Vendor Procedures and Reporting | 5 |
| 3. Contact Information | 6 |
| 4. Approval and Authorization | 8 |
| APPENDIX A: Security Incident Prioritization: Urgency and Impact | 9 |
| APPENDIX B: Incident Response Roles, Responsibilities, and Contacts | 12 |
| Senior Leadership | 12 |
| Operational Teams | 13 |
| Support Teams | 14 |
| Document Revision History | 16 |
1. Introduction and Purpose The Incident Response Plan (IRP) outlines the roles and responsibilities of system users, key contacts, and procedures for reporting incidents on ACF-owned systems. It includes steps for identifying, recording, classifying, and directing incidents to the right support group, guiding the resolution process. The plan provides the necessary information for the ACF Incident Response Team (IRT) to effectively address security and privacy incidents that could impact the system or its data.
The processes outlined in this plan depend on the ACF Incident Response Policy, the Computer Security Incident Management Plan (CSIM), the Breach Response Plan, and standard operating procedures (SOPs) used by the Incident Response Team (IRT). The IRT comprises personnel from the ACF Privacy and Security Operations Teams. Comment by Kase, Whitney (ACF) (CTR): Add requirement to document Recovery procedures.
2. Incident Response Notifications and Procedures Once a security incident or data breach has been identified on an ACF system, the following notifications and procedures are followed.
The ACF Incident Response Policy defines an incident as “any observable occurrence in a system or network,” including viruses, malicious user activity, and vulnerabilities associated with highly interconnected technology. Data breaches include any unauthorized sharing of Personally Identifiable Information (PII). PII includes, but is not limited to, name, Social Security number (SSN), date of birth, mother’s maiden name, financial records, email address, driver’s license number, passport number, and health information.
2.1 User Reporting of Security Incident
All users must report any security events they notice. This includes when an application acts strangely, if they access information they shouldn’t, or if they spot something unusual during security checks.
If a security incident is suspected or observed, users should inform their supervisor or manager and email the ACF Incident Response Team (IRT) at ACF_IRT@acf.hhs.gov.
2.2 ACF Incident Response Team (IRT) Procedures and Reporting
1) The ACF IRT Incident Coordinator confirms receipt of a reported incident and creates a ticket in HHS Archer, initiating the following:
a) If PII is involved, a Data Breach incident is automatically created, and notifications are sent to:
i) The ACF Privacy Team Breach Response Lead
ii) The OCIO SecOps team member assigned to the case
b) If PII is not involved, an IT Security incident is created, and a notification is sent only to the OCIO SecOps team member.
2) After creating the ticket, the Incident Coordinator notifies the ACF CIO, CISO, OCIO IT Security Specialist, and others (e.g., SO, COR) to coordinate the response.
3) The assigned Privacy or SecOps team member contacts the incident reporter and sends them the CSIRC Security Incident Report Form.
4) Based on incident priority level, the Privacy and SecOps members follow established SOPs and procedures, working with system contacts to resolve the issue.
5) The Privacy and SecOps members update the HHS Archer ticket with progress and upload relevant evidence.
6) The Incident Coordinator works with the system SSPO and provides regular status updates (weekly or as needed) to the ACF CIO, CISO, and OCIO Security Specialist.
7) Once the incident is resolved, the Privacy and SecOps teams request closure in HHS Archer. Comment by Kase, Whitney (ACF) (CTR): Add a requirement for Tabletops?
2.3 Vendor Procedures and Reporting
Please email ACF_IRT@acf.hhs.gov to request a CSIRC Security Incident Report form.
3. Contact Information The table below should provide contact information for all levels of the project. These contacts include the various teams and team leads that are involved in responding to an incident. See Appendix B for detailed roles and responsibilities.
Table 2. Contact Information
ACF Primary Incident Response Contacts
| Name |
| Organization / Title |
| Address |
| Phone Number |
| N/A |
| ACF IRT |
| 330 C Street SW Washington, DC |
| N/A |
| ACF_IRT@acf.hhs.gov |
| N/A |
| ACF Privacy Team |
| 330 C Street SW Washington, DC |
| N/A |
| OCIO.Privacy@acf.hhs.gov |
| N/A |
| ACF Security Operation (SecOps) Team |
| 330 C Street SW Washington, DC |
| N/A |
| ACF.OCIO.Cybersecurity@acf.hhs.gov |
ACF OCIO Senior Leadership
| Name |
| Organization / Title |
| Address |
| Phone Number |
| Add name | Chief Information Officer |
| 330 C Street SW Washington, DC | |
| Add phone | |
| Add email |
| Add name | Chief Information Security Officer (CISO) |
| 330 C Street SW Washington, DC | |
| Add phone |
Add email
| Add name | Senior Officer for Privacy (SOP) |
| 330 C Street SW Washington, DC | |
| Add phone |
Add email
ACF OCIO IT, Security, and Privacy Support Contacts
| Name |
| Organization / Title |
| Address |
| Phone Number |
| N/A |
| ACF OCIO Service Desk |
| 330 C Street SW Washington, DC |
| Add phone |
OCIO.Service.Desk@acf.hhs.gov
| Add name | ACF OCIO Operations System Admin |
| 330 C Street SW Washington, DC | |
| Add phone |
Add email
| Add name | System Security and Privacy Officer (SSPO) |
| 330 C Street SW Washington, DC | |
| Add phone |
Add email
| Add name | Information System Security Engineer (ISSE) |
| 330 C Street SW Washington, DC | |
| Add phone |
Add email
| Add name | Information System Security Manger (ISSM) |
| 330 C Street SW Washington, DC | |
| Add phone |
Add email
ACF Program Office Contacts
| Name |
| Organization / Title |
| Address |
| Phone Number |
| Add name | Business Owner (BO) |
| Add address | |
| Add phone |
Add email
| Add name | System Owner (SO) |
| Add address |
Add phone
Add email
| Add name | Vendor P.M. |
| Add address | |
| Add phone |
Add email
| Add name | Vendor Technical P.O.C. |
| Add address |
Add phone
Add email
4. Approval and Authorization The information contained in this IRP has been reviewed and approved by the following authority:
System Owner Digital Signature – Date
APPENDIX A: Security Incident Prioritization: Urgency and Impact Prioritization is established by ACF using the impact, urgency, and metrics defined in the tables below. Incident Response prioritization is managed via the ACF CISM Plan.
Not all incidents or events have equal impact on the organization. Once categorized, each event or incident is evaluated for how it may affect the environment. This initial assessment helps the ACF IRT investigate and remediate detected and reported issues by prioritizing events to maximize limited personnel resources.
The two key criteria to be evaluated are impact and urgency:
· Impact specifies the overall effect of an event or incident. This includes the number of affected users and the criticality of the affected system or data. Impact is also used to qualify the effect of reputation loss on the department, agency, or organization.
· Urgency combines the time it takes an incident to significantly impact business, the criticality of the system under attack, and the sensitivity of the data exposed.
Prioritization levels indicate two separate but related criteria that determine the level of effort required by the ACF IRT to perform the steps in the incident response lifecycle.
· Response time is the expected response time for creating an incident ticket after an event or incident is detected or reported. This includes the initial triage assessment and categorization steps.
· Resolution time is the expected window of time the ACF IRT has to perform their investigation, contain the effect, and apply mitigation strategies to the event or incident. Final resolution with remediation and root cause analysis is not accounted for in this calculation, as these events may take weeks or months.
The priority level of an event or incident is calculated as a combination of impact and urgency. These components are defined below.
Table 1. Impact and Urgency Descriptions
| Impact Code |
| Example |
| Urgency Code |
| Example |
Extensive / Widespread
| An event or incident affecting all or most ACF assets across multiple data centers and applications. The exposed data is sensitive PII and has been verified to be exposed to the public. User data loss affects 500 unique individuals or more. |
| Severe |
| An incident or event affecting critical assets or high-value applications, or resulting in a complete work |
| Significant / Large |
| An event or incident affecting large portions of ACF assets in one or more data centers and affecting two or more applications. The exposed data is sensitive PII or is likely to be exposed to the public. User data loss affects 100 unique individuals or more. |
| High |
| An incident or event affecting core support assets or high-value applications, or significantly impacting business operations. With data exposure, the exposed data is sensitive PII. |
Moderate / Limited
| An event or incident affecting some ACF assets and at least one application. The exposed data is PII. User data loss affects 50 unique individuals or more. |
| Medium |
| An incident or event affecting assets or applications resulting in a moderate impact on business operations, but a workaround exists. With data exposure, the exposed data is PII. |
| Minor / Localized |
| An event or incident affecting some ACF assets. The exposed data may contain PII. User data loss affects fewer than 50 unique individuals. |
| Low |
| An incident or event resulting in little to no impact on business operations. With data exposure, the data exposed is not PII. |
Table 2. Incident Response Prioritization Levels
| Priority Level |
| Response Time |
| Resolution Time |
| PO |
| 4 hrs. |
| 16 hrs. |
| P1 |
| 8 hrs. |
| 24 hrs. |
| P2 |
| 16 hrs. |
| 40 hrs. |
| P3 |
| 24 hrs. |
| 56 to 72 hrs. |
Table 3. Incident Response Matric
| Urgency |
| Impact Extensive / Widespread |
| Impact Significant / Large |
| Impact Moderate / Limited |
| Impact Mnor / Localized |
| Severe |
| PO |
| PO |
| P1 |
| P2 |
| High |
| P1 |
| P1 |
| P2 |
| P3 |
| Medium |
| P2 |
| P2 |
| P3 |
| P3 |
| Low |
| P3 |
| P3 |
| P3 |
| P3 |
APPENDIX B: Incident Response Roles, Responsibilities, and Contacts Senior Leadership ACF Chief Information Officer (CIO)
· Establish, implement, and enforce the ACF Incident Response (IR) and Handling policy.
· Provide management oversight of the IR and handling process.
· Inform ACF senior leadership of any significant IT security or privacy incident (for example, major data compromise).
· If any employment action may be appropriate after an incident investigation is over, provide recommendations to the Office of Workforce Planning and Development.
ACF Chief Information Security Officer (CISO)
· Ensure ACF-wide implementation of plans and procedures related to IT security and privacy incident response.
· Oversee and manage the resources that support ACF IRT operations.
· Notify the CIO of any significant IT security or privacy incident.
ACF Senior Official for Privacy (SOP)
· Coordinate with the ACF IRT and the HHS Privacy Program about reports of a PII breach.
ACF Program Office Leadership
· Disseminate and ensure compliance with policies, plans, and procedures related to security and privacy incident responses in their respective office.
· Notify employees of any changes to existing policy or creation of new policy about the IR program.
· Cooperate with the ACF CISO and IRT on investigations into security and privacy incidents originating in their respective office.
Operational Teams
ACF IRT
· Draw on personnel from the functional teams in the OCIO: Enterprise Security, Security Operations, Privacy Program, and IT Governance.
· Establish and maintain IT security and privacy IR capabilities ensuring these capabilities are performed by the team or on their behalf.
· Report IT security and privacy incidents to the HHS CSIRC following the CSIRC Concept of Operations (CONOPS), specifically for incidents involving the actual or suspected loss of control over PII.
· Serve as the primary POC for HHS CSIRC and the HHS Privacy Program.
· Coordinate with the ACF Senior Official for Privacy in OCIO about PII breaches following IRT processes.
· Coordinate the ACF-wide response to IT security vulnerabilities, threats, and incidents.
· Facilitate information sharing across ACF regarding IT security vulnerabilities, threats, and incidents.
· Augment existing analysis capabilities and forensic services regarding security vulnerabilities, threats, and incidents.
· Comply with all reporting requirements and follow guidance from US-CERT and NIST.
· Report incidents involving confirmed or suspected violations of the law, or employee or contractor misconduct, to the Office of Inspector General (OIG) following HHS policies and procedures.
· Coordinate and provide IR support for ACF systems, applications, or data managed or hosted by another operating division or organization.
Enterprise Security
· Provide subject matter expertise on the overall impact assessment.
Security Operations
· Operate, manage, and maintain security tools.
· Create and deploy incident response use cases for alerts and investigations.
· Provide technical support and investigation response for computer security-related events and incidents.
Privacy Program
· Investigate events that affect privacy or constitute policy violations.
· Provide subject matter expertise for any event or incident that involves loss of confidentiality or integrity of ACF data.
IT Governance
· Provide oversight and subject matter expertise on policy and compliance-related issues.
ACF OCIO Operations Team
· Provide subject matter expertise on technical issues related to investigated events and incidents.
· Conduct data collection on behalf of the Security Operations Team on systems under its administrative control.
Support Teams Program Management Offices of Affected Systems or Assets Program Office System Owner
· Communicate to users, developers, and administrators of the system owner's designated information system about security and privacy IR requirements as outlined in this policy and additional plan and procedure documentation.
· Notify the ACF CISO and IRT of any suspected or confirmed IT security or privacy incidents occurring on the information system within one hour of discovery.
· Cooperate with ACF CISO and IRT on any investigation into security or privacy incidents affecting their information system.
· Coordinate communication between ACF IRT and other ACF POCs with System PM and the technical support team.
· Inform the Contracting Officer's Representative (COR) of the vendor contract of any changes needed to address the security incident.
· Contracting Officer’s Representative (COR)
· Communicate with the Contracting Officer (CO) and the contract's PM, ensuring any concerns, deficiencies, or changes to the contract are made to address the security incident.
· Track all vendor activities to address the security incident, which may impact contract performance, resources, and cost.
HHS CSIRC
· Serve as the primary entity responsible for maintaining HHS-wide operational IT security situational awareness and determining the overall IT security risk posture.
· Report all IT security and privacy incidents to US-CERT.
· Serve as the primary POC with US-CERT.
· Report to the ACF IRT on any action taken by the OIG regarding an ACF-reported incident involving confirmed or suspected violations of the law, or employee or contractor misconduct.
External Hosting and Operations Personnel
· Notify the ACF CISO, IRT, and System Owner of any suspected or confirmed IT security or privacy incidents involving ACF infrastructure, information systems, and data within one hour of discovery.
· Notify the ACF CISO and IRT of any suspected or confirmed IT security or privacy incidents occurring on ACF-managed networks within one hour of discovery.
· Ensure that security and privacy requirements are implemented and enforced.
· Assist in the incident investigation efforts and coordinate with the IRT to execute remediation activities.
External Organizations
· Notify the Program Office, ACF CISO, and IRT of any suspected or confirmed IT security or privacy incidents involving ACF data managed by the organization within one hour of discovery.
· Assist in the incident investigation efforts and coordinate with the ACF IRT to execute remediation activities.
Document Revision History
| Date |
| Version |
| Comments |
Version 1.0 Incident Response Plan 1 image1.png image2.png
File details come from the government source that posted it. Updated .