CCI-002807
CCI-002807 Definition
| Status | |
| Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
Determine if [IR-09_ODP[02]; personnel or roles to be alerted of the information spill using a method of communication not associated with the spill is/are defined] is/are alerted of the information spill using a method of communication not associated with the spill.
Validation Procedures
Examine: [SELECT FROM: Incident response policy; procedures addressing information spillage; incident response plan; system security plan; records of information spillage alerts/notifications; list of personnel who should receive alerts of information spillage; list of actions to be performed regarding information spillage; other relevant documents or records]. Interview: [SELECT FROM: Organizational personnel with incident response responsibilities; organizational personnel with information security responsibilities]. Test: [SELECT FROM: Organizational processes for information spillage response; mechanisms supporting and/or implementing information spillage response actions and related communications].