CCI-000848
CCI-000848 Definition
The organization reviews the incident response plan on an organization-defined frequency.
Status | |
Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
The organization being inspected/assessed will conduct reviews of its incident response plan at least annually. DoD has defined the frequency as at least annually (incorporating lessons learned from past incidents).
Validation Procedures
The organization conducting the inspection/assessment obtains and examines the incident response plan to validate it is current and has been reviewed within the last year. DoD has defined the frequency as at least annually (incorporating lessons learned from past incidents).
Compelling Evidence
1.) Signed and dated Incident Response Plan, referencing change log and/or version section