CCI-002787
CCI-002787 Definition
| Status | |
| Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
Determine if there is coordination with [IR-04(08)_ODP[01]; external organizations with whom Organizational incident information is to be coordinated and shared are defined] to correlate and share [IR-04(08)_ODP[02]; incident information to be correlated and shared with organization-defined external organizations are defined] to achieve a cross-organization perspective on incident awareness and more effective incident responses.
Validation Procedures
Examine: [SELECT FROM: Incident response policy; procedures addressing incident handling; list of external organizations; records of incident handling coordination with external organizations; incident response plan; system security plan; privacy plan; other relevant documents or records]. Interview: [SELECT FROM: Organizational personnel with incident handling responsibilities; organizational personnel with information security and privacy responsibilities; personnel from external organizations with whom incident response information is to be coordinated, shared, and correlated]. Test: [SELECT FROM: Organizational processes for coordinating incident handling information with external organizations].