CCI-002720
CCI-002720 Definition
Status | |
Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
The organization being inspected/assessed incorporates the detection of unauthorized security-relevant changes to the information system defined in SI-7 (7), CCI 2719 into the organizational incident response capability.
Validation Procedures
The organization conducting the inspection/assessment examines the organizational incident response capability to ensure the organization being inspected/assessed incorporates the detection of unauthorized security-relevant changes to the information system defined in SI-7 (7), CCI 2719.
Compelling Evidence
1.) Signed and dated System security plan defines which unauthorized security-relevant changes will be a part of the organization-level Incident Response Plan. 2.) Organization-level incident response plan in which unauthorized security-relevant changes will be a part of the organization-level Incident Response Plan.