CCI-000838
CCI-000838 Definition
| Status | |
| Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
Determine if system vulnerabilities associated with reported incidents are reported to [IR-06(02)_ODP; personnel or roles to whom system vulnerabilities associated with reported incidents are reported to is/are defined].
Validation Procedures
Examine: [SELECT FROM: Incident response policy; procedures addressing incident reporting; incident response plan; system security plan; privacy plan; security incident reports and associated system vulnerabilities; other relevant documents or records]. Interview: [SELECT FROM: Organizational personnel with incident reporting responsibilities; organizational personnel with information security and privacy responsibilities; system/network administrators; personnel to whom vulnerabilities associated with security incidents are to be reported]. Test: [SELECT FROM: Organizational processes for incident reporting; mechanisms supporting and/or implementing the reporting of vulnerabilities associated with security incidents].