5.26 Response to information security incidents
Requires information security incidents to be responded to in accordance with documented procedures, rather than improvised case by case.
5
artefacts
1
held by a system
3
at each review
hard
to go live
Document repository
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Closure records showing the criteria for closure were met · Document repository
periodic reviewEvidence produced at each review
- Incident records carrying detection, containment, eradication and recovery timestamps and the actions taken at each stage · Document repository
- Evidence of decisions taken during response and by whom, including any decision to preserve rather than eradicate · Document repository
- Communication records to internal stakeholders, affected parties, authorities and customers where required · Policy repository / GRC workspace
governing documentDocuments that govern the control
- Documented response procedures per incident type, and evidence they were followed in actual incidents · Policy repository / GRC workspace
First move
Mostly documents and reviews. Pull the 1 system-held artefact from your Document repository on a schedule; put the documents under version control with an owner and review date, and log each review as a dated record with a named reviewer.
Common gaps auditors find
- Procedures exist but the incident record contains only an outcome, with no trace that the procedure was applied
- Containment achieved while the underlying weakness stays open, so the incident recurs
- Timestamps recorded at ticket creation and closure only, so response time cannot be measured
- Decisions made during the response undocumented, which is fatal if the incident later becomes a legal matter
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheet5.25 Assessment and decision on information security events · 5.27 Learning from information security incidents