IR-04—External Communication of Incidents
>Control Description
Theme
Type
Policy/Standard
Incident Management Policy>Implementation Guidance
1. Ensure that following details are documented in Incident Response Plan and Standard: • information about external party dependencies • criteria for notification to external parties as required by policy in the event of a security breach • contact information for authorities (e.g., law enforcement, regulatory bodies, etc.) • provisions for updating and communicating external communication requirement changes 2. Establish a process that flags the alerts as the defined escalation metrics.
>Testing Procedure
1. Inspect the Incident Response Plan and Standard to determine whether the following are documented: • information about external party dependencies • criteria for notification to external parties as required by policy in the event of a security breach • contact information for authorities (e.g., law enforcement, regulatory bodies, etc.) • provisions for updating and communicating external communication requirement changes 2. Review the procedure for alert escalation
>Audit Artifacts
>Framework Mappings
Cross-framework mappings provided by Adobe CCF Open Source under Creative Commons License.
Ask AI
Configure your API key to use AI features.