RS.MA-01 The incident response plan is executed in coordination with relevant third parties once an incident is declared
The incident response plan is executed in coordination with relevant third parties once an incident is declared.
5
artefacts
1
held by a system
1
at each review
hard
to go live
Vendor register / contract repository
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Vendor activation log during real incidents · SIEM / log platform
periodic reviewEvidence produced at each review
- Joint exercise records with the IR vendor · Vendor register / contract repository
governing documentDocuments that govern the control
- Incident response plan with third party invocation · Vendor register / contract repository
- Retainer contract evidence for IR vendor · Vendor register / contract repository
- Coordination procedure with law enforcement · Policy repository / GRC workspace
First move
Mostly documents and reviews. Pull the 1 system-held artefact from your SIEM / log platform on a schedule; put the documents under version control with an owner and review date, and log each review as a dated record with a named reviewer.
Common gaps auditors find
- Retainer in place but contact path untested
- Coordination with law enforcement absent
- Joint exercises infrequent
- Activation log incomplete
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetRS.CO-03 Information is shared with designated internal and external stakeholders · RS.MA-02 Incident reports are triaged and validated