CCI-002791
CCI-002791 Definition
| Status | |
| Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
Determine if incident information is reported to [IR-06_ODP[02]; authorities to whom incident information is to be reported are defined].
Validation Procedures
Examine: [SELECT FROM: Incident response policy; procedures addressing incident reporting; incident reporting records and documentation; incident response plan; system security plan; privacy plan; other relevant documents or records]. Interview: [SELECT FROM: Organizational personnel with incident reporting responsibilities; organizational personnel with information security and privacy responsibilities; personnel who have/should have reported incidents; personnel (authorities) to whom incident information is to be reported; system users]. Test: [SELECT FROM: Organizational processes for incident reporting; mechanisms supporting and/or implementing incident reporting].