UC San Diego
Faculty and Staff
Site Search
Blink Logo
A-Z Sites Department Index
  • Blink Tabs
    • Buy & Pay
    • Facilities & Services
    • Faculty Resources
    • Finance
    • Human Resources
    • Research
    • Safety
    • Student / Class Info
    • Technology
    • Travel
  • Personal Tools
    • At Your Service via AYSO
    • At Your Service via SSO
    • Compensation Calculator
    • Enrollment Central
    • Job Bulletin
    • My Directory
    • My LeaveBalances
    • My Time
    • My Training
    • My Travel
    • SkillSoft eLearning
    • All tools
  • Business Tools
    • APOL
    • Connexxus
    • Marketplace
    • Title & Pay Look-up
    • MyApprovals
    • MyDashboard
    • MyEvents
    • MyFunds
    • MyTravel
    • EmployeeLink
    • FinancialLink
    • TravelLink
    • All tools
  • Instruction Tools
    • ASSIST
    • Class Lists
    • Degree Audit (DARs)
    • Find a Student
    • Majors List
    • Minors List
    • Schedule of Classes
    • Enrollment and Waitlists
    • WebCT
    • All tools
  • Research Tools
    • Proposal Repository
    • Faculty Expertise
    • Forms lister
    • Get Proposal #
    • Shared Facilities
    • FinancialLink
    • TravelLink
    • MyEffort
    • MyFunds
    • My Research Safety
    • MyTravel
    • All tools
  • Blink Home 
  • Technology 
  • Security 
  • Computer Incident Response Team 
  • Reporting an Incident

How to Report a Computer Security Incident

Last updated September 11, 2009 8:45:25 AM PDT
Give more feedback

If you are a system administrator, follow these steps to work with the Computer Incident Response Team (CIRT) and help:

  • Manage security incidents at UCSD
  • Combat rising security and accountability risks
  • Reduce associated costs

If you are not a system administrator and suspect a violation of your computer's security, contact your department's technical support person immediately. After hours, call the ACT Help Desk, (858) 534-1853.

Expand all

1. Don't touch the machine or system.

  • Do not turn off the machine.
  • Do not remove the machine from the network.
  • Do not look at the system to see what files are on it, or what might have been touched.

2. Find out what constitutes a security incident.

A security incident occurs when an unauthorized entity gains access to UCSD computing or network services, equipment, or data.

Review typical situations:

  • You detect or get a report of a physical or criminal act, such as theft of a laptop, desktop computer, or PDA.
  • A law enforcement representative contacts the University regarding a security incident.
  • You suspect that a computer or other network device may have been compromised to allow the viewing, transferring, or alteration of student data, personal information, medical data managed under HIPAA, or other legally regulated data.
  • You suspect a security problem with a desktop workstation and the person using the workstation:
    • Works with personnel or financial data
    • Connects to UCSD business databases (because the password may have been revealed, exposing this data)
    • Works with personal information used for medical services or human subjects
    • Submits student grades
  • You suspect that a multi-user machine, a file, or a Web server may have been jeopardized.

Consider other questionable circumstances:

  • Disruptive virus or Denial of Service (network is flooded with traffic) attacks are not security incidents because no unauthorized access was achieved.
  • An unsuccessful attempt may not be a security incident, but may warrant investigation and action by the system administrator or the system's owner.

    3. Request assistance from UCSD's Computer Incident Response Team (CIRT).

    Report any incident you consider a possible threat.

    • Contact the ACT Help Desk, (858) 534-1853. The Help Desk will contact the on-call CIRT representative, who will respond.
    • Note: The earlier you contact CIRT, the more likely it is that CIRT will be able to help.

    4. Cooperate with CIRT.

    CIRT will work with you to:

    • Preserve and use forensic evidence to discover the extent of the intrusion
    • Determine and minimize risk and the possibility of future risk to the University
    • Provide and maintain smooth and consistent interaction with law enforcement and university management

    Note: CIRT cannot assist with cleanup and data recovery, except as they pertain to the situations above.

    • Learn about the CIRT process for dealing with security incidents.

    Expand all

    For more information, e-mail CIRT.

    Technology

    Computer Incident Response Team

    • Reporting an Incident

    Departments


    ACMS

    ACT

    UC San Diego 9500 Gilman Dr. La Jolla, CA 92093 (858) 534-2230
    Copyright ©2009 Regents of the University of California. All rights reserved.
    • Terms & Conditions
    • Feedback
    • About Us
    • Accessibility
    • Emergency Info