An information security incident is an event that violates security policies or standards, or threatens IT systems or resources. This can include disclosing sensitive information such as health records, making unauthorized changes to Commonwealth data, or causing unnecessary disruption to Commonwealth resources or networks. COT’s response plan reacts to security incidents to eliminate the threat and return the systems and resources to normal and secure business operations.
When a potential security incident is identified, policy CIO-090 requires you to contact the Commonwealth Service Desk immediately by calling 502-564-7576. The Security Incident Report Form (COT-F012) may be used, if helpful. In the event that the incident is sensitive in nature and you wish to bypass the Commonwealth Service Desk, you may contact the Security Administration Branch at COTSecurityServicesISS@ky.gov or 502-564-1532 directly.