CCI-002782
CCI-002782 Definition
Implement an incident handling capability for incidents involving insider threats.
| Status | |
| Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
Determine if an incident handling capability is implemented for incidents involving insider threats.
Validation Procedures
Examine: [SELECT FROM: Incident response policy; procedures addressing incident handling; mechanisms supporting incident handling; system design documentation; system configuration settings and associated documentation; incident response plan; system security plan; audit records; other relevant documents or records]. Interview: [SELECT FROM: Organizational personnel with incident handling responsibilities; organizational personnel with information security responsibilities]. Test: [SELECT FROM: Incident handling capability for the organization].