{"data":{"id":"us-in/ic-4-13.1-1-1.5","jurisdiction":"us-in","citation":"IC 4-13.1-1-1.5","heading":"\"Cybersecurity incident\"","body":"Sec. 1.5. (a) \"Cybersecurity incident\" means a malicious or suspicious occurrence that consists of one (1) or more of the categories of attack vectors described in subsection (b) and defined on the office's website that:\n(1) jeopardizes or may potentially jeopardize the confidentiality, integrity, or availability of an information system, an operational system, or the information that such systems process, store, or transmit;\n(2) jeopardizes or may potentially jeopardize the health and safety of the public; or\n(3) violates security policies, security procedures, or acceptable use policies.\n(b) A cybersecurity incident may consist of one (1) or more of the following categories of attack vectors:\n(1) Ransomware.\n(2) Business electronic mail compromise.\n(3) Vulnerability exploitation.\n(4) Zero-day exploitation.\n(5) Distributed denial of service.\n(6) Website defacement.\n(7) Other sophisticated attacks as defined by the chief information officer and that are posted on the office's website.","path":["TITLE 4. STATE OFFICES AND ADMINISTRATION","ARTICLE 13.1. OFFICE OF TECHNOLOGY","Chapter 1. Definitions"],"source_url":"https://iga.in.gov/ic/2026/Title_4.html#4-13.1-1-1.5","current_through":"2026","vintage":"2026","retrieved_at":"2026-08-30T06:26:00Z","sha256":"2ad8e4354da68b019b8e900d0bf20241a5a5f380be1a4e3d4ea3b04c91c05984","source_id":"us-in","stale":false,"prev":"us-in/ic-4-13.1-1-1.3","next":"us-in/ic-4-13.1-1-2"},"notice":"GroundRules: Original legal text. Not legal advice."}
