IR-8 Incident response plan
Requires an incident response plan that sets the roadmap and structure for the capability, fits it to the organization, defines reportable incidents and success metrics, defines the resources and management support neede
5
artefacts
1
held by a system
2
at each review
hard
to go live
Policy repository / GRC workspace
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Defined metrics for measuring incident response capability · Policy repository / GRC workspace
periodic reviewEvidence produced at each review
- Distribution record to the defined recipients · Document repository
- Review and update history including changes after incidents or exercises · Document repository
governing documentDocuments that govern the control
- Approved incident response plan with roles, structure and reportable incident definitions · Policy repository / GRC workspace
- Access controls protecting the plan from unauthorized disclosure or change · Policy repository / GRC workspace
First move
Mostly documents and reviews. Pull the 1 system-held artefact from your Policy repository / GRC workspace on a schedule; put the documents under version control with an owner and review date, and log each review as a dated record with a named reviewer.
Common gaps auditors find
- Plan defines severity levels but never defines what counts as a reportable incident
- Plan stored only on the system it is meant to help recover
- Updates made without redistribution, so responders hold an outdated copy
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetIR-7 Incident response assistance · IR-9 Information Spillage Response. Respond to information spills by: Assigning [organization-defined] with responsibility for responding to information spills; Identifying the specific information involved in the system contamination; Alerting [organization-defined] of the information spill using a