CCI-004141
CCI-004141 Definition
| Status | |
| Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
Determine if: - an incident handling capability is coordinated for insider threats. - the coordinated incident handling capability includes [IR-04(07)_ODP; entities that require coordination for an incident handling capability for insider threats are defined].
Validation Procedures
Examine: [SELECT FROM: Incident response policy; procedures addressing incident handling; incident response plan; insider threat program plan; insider threat CONOPS; system security plan; privacy plan; other relevant documents or records]. Interview: [SELECT FROM: Organizational personnel with incident handling responsibilities; organizational personnel with information security and privacy responsibilities; organizational personnel/elements with whom the incident handling capability is to be coordinated]. Test: [SELECT FROM: Organizational processes for coordinating incident handling].