There are five actors:
There four phases:
Done by the Department.
A suspicious activity is observed. This might or might not lead to an incident report. There are two cases that require a report.
If restricted data may have been accessible to unauthorized persons, the incident must be reported.
If sensitive data was accessed by unauthorized persons, the incident must be reported.
Done by the Office of Cybersecurity, with assistance from the Department.
The investigation determines whether or not leadership needs to make a decision about notification.
Done by the CIO, the Administrative Leadership Team (ALT), and University Communications, with assistance from the Department and the Office of Cybersecurity.
The CIO organizes the ALT. The ALT reviews the investigation report and decides whether or not to notify the affected persons. If so, notification is done, with provision to respond to inquiries from the press and those who were notified.
The ALT also evaluates and follows up on other obligations the university might have.
The process always ends with post-incident activities by all who were involved up to that point.
Please address questions or comments to itpolicy@cio.wisc.edu.