CCI-002808
CCI-002808 Definition
The organization responds to information spills by isolating the contaminated information system or system component.
Status | |
Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
The organization being inspected/assessed documents within their incident response plan, a process to isolate the contaminated information system or system component.
Validation Procedures
The organization conducting the inspection/assessment obtains and examines the incident response plan as well as after action reports of incidents to ensure that the organization being inspected/assessed isolates contaminated information system or system component.
Compelling Evidence
1.) Signed and dated Incident Response Plan, referencing information system contamination section 2.) Incident response after action reports