CCI-000850
CCI-000850 Definition
| Status | |
| Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
Determine if: - incident response plan changes are communicated to [IR-08_ODP[06]; incident response personnel (identified by name and/or by role) to whom changes to the incident response plan is/are communicated are defined]. - incident response plan changes are communicated to [IR-08_ODP[07]; Organizational elements to which changes to the incident response plan are communicated are defined].
Validation Procedures
Examine: [SELECT FROM: Incident response policy; procedures addressing incident response planning; incident response plan; system security plan; privacy plan; records of incident response plan reviews and approvals; other relevant documents or records]. Interview: [SELECT FROM: Organizational personnel with incident response planning responsibilities; organizational personnel with information security and privacy responsibilities]. Test: [SELECT FROM: Organizational incident response plan and related organizational processes].