incident-response

incident-response Controls

21 controls across 4 frameworks.

CISA CPG

HIPAA

NIST CSF

de-ae-4

The estimated impact and scope of adverse events are understood

Detect / Adverse Event Analysis

de-ae-6

Information on adverse events is provided to authorized staff and tools

Detect / Adverse Event Analysis

de-ae-8

Incidents are declared when adverse events meet the defined criteria

Detect / Adverse Event Analysis

gv-sc-2

Cybersecurity roles and responsibilities for suppliers and partners are established and coordinated

Govern / Cybersecurity Supply Chain Risk Management

gv-sc-8

Relevant suppliers are included in incident planning, response, and recovery activities

Govern / Cybersecurity Supply Chain Risk Management

id-im-4

Incident response plans and cybersecurity plans are established, maintained, and improved

Identify / Improvement

rc-co-3

Recovery activities and progress in restoring operational capabilities are communicated to designated internal and external stakeholders

Recover / Incident Recovery Communication

rc-co-4

Public updates on the incident and ongoing recovery are shared using approved methods and messaging

Recover / Incident Recovery Communication

rc-rp-5

The integrity of restored assets is verified, the asset is deemed secure, and normal operating status is confirmed

Recover / Incident Recovery Plan Execution

rs-an-3

Forensics are performed

Respond / Incident Analysis

rs-ma-1

Execute the incident response plan in coordination with relevant third parties

Respond / Incident Management

rs-mi-1

Incidents are contained

Respond / Incident Mitigation

rs-mi-2

Incidents are eradicated

Respond / Incident Mitigation

SOC2