12.10.5 IRP includes monitoring and response to security control alerts
The incident response plan includes monitoring and responding to alerts from security monitoring systems including IDS/IPS, network and host-based file integrity monitoring, change-detection mechanisms, anti-malware solu
5
artefacts
4
held by a system
1
at each review
easy
to go live
SIEM / log platform
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- IRP section listing alert sources and triage paths · SIEM / log platform
- Sample triaged alerts with timeline · SIEM / log platform
- Coverage matrix of alert sources to IRP · SIEM / log platform
- Monitoring tool inventory · SIEM / log platform
periodic reviewEvidence produced at each review
- SIEM playbook integration evidence · SIEM / log platform
governing documentDocuments that govern the control
none for this control
First move
Automate the pull from your SIEM / log platform. Retention and alert rules exported from the SIEM; review evidence is the closed-alert record with reviewer and time.
Common gaps auditors find
- Alert sources missing from IRP
- No playbooks
- Coverage gaps
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheet12.10.4.1 Periodic IR responder skill review · 12.10.6 IRP refined based on lessons learned