Any data security incident involving a University-owned or personal device containing sensitive University data is serious. Responding to data security incidents promptly and efficiently helps protect the University's assets (e.g., data, computers, networks) and ensures compliance with state and federal law, and University policy.
IT Administrators can use this page to learn more about the steps they need to take if they suspect an incident involving a device in their department.
All data security incidents involving University-owned or personal devices containing sensitive University data are serious, and may require an Incident Report (see below for more details about responses to specific data security incidents).
If a data security incident requires an incident report, email security@umass.edu the following information:
IT Administrators who suspect a data security incident in their department or who were notified of a potential incident need to complete the following steps:
Note: This is a general overview of the incident response process. Depending on the complexity of the incident, additional steps may be required.
If the incident is confirmed:
Computers compromised by malware are the most common data security incident on campus. Departments can choose to handle portions of an incident internally (using the Malware Incident Response Checklist) or contact UMass Amherst IT at security@umass.edu as soon as possible.
If a computing device that contains sensitive University data is accessed without permission via stolen or compromised credentials, credentials lost to phishing scams, and other attempts to access a device without authorization (e.g., former employees, etc.):
At a minimum, include the nature of the incident (e.g., response to a phishing scam), the approximate date and time when the incident occurred, your email address, and campus phone number.
If a computing device, including departmental laptops, USB drives, cell phones, other devices that may contain sensitive data or personal computing devices with sensitive University data, is lost or stolen:
Report the lost or stolen device at 413-545-2121. UMPD may be able to locate your item(s) faster if you have registered them.
For University-owned devices, report the incident to the University Procurement Department at 413-545-0361.
You will be asked to provide information on the nature of the incident (e.g., lost computer), the approximate date and time when the device was lost or stolen (or when it was discovered to be missing), your email address, and campus phone number.
Be sure to change your IT Account password in SPIRE, and any other password that may have been exposed.
Contact the mobile device service provider and request that the contents of your device be wiped remotely.