IR-1 Policy and procedures for incident response
Requires an incident response policy with supporting procedures to be developed, approved, disseminated to defined personnel, owned by a named official, and reviewed and updated on a defined frequency and after defined e
system holds itEvidence a system already holds
none for this control
periodic reviewEvidence produced at each review
none for this control
governing documentDocuments that govern the control
- Approved incident response policy with scope, approver and date · Policy repository / GRC workspace
- Evidence the incident response policy reached the personnel or roles it defines · Policy repository / GRC workspace
- Written designation of the official accountable for the incident response policy and procedures · Policy repository / GRC workspace
- Procedures for detection, triage, containment, eradication, recovery and reporting · Policy repository / GRC workspace
- Review record for the incident response policy and procedures against the defined frequency and triggering events · Policy repository / GRC workspace
First move
Common gaps auditors find
- Policy silent on privacy incidents and personal data breach obligations
- Procedures assume an on-premises estate and omit cloud and provider incidents
- Review only occurs after a major incident
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetIA-13 Identity Providers and Authorization Servers. Employ identity providers and authorization servers to manage user, device, and non-person entity (NPE) identities, attributes, and access rights supporting authentication and authorization decisions in accordance with [organization-defined] using · IR-2 Incident response training