Show/Hide Toolbars

ABCI Consultants

Guidance for NIST 800-171 Assessment & Compliance

Navigation: IR-FAMILY: INCIDENT RESPONSE

IR-4 INCIDENT HANDLING

Scroll Prev Top Next More

Applicable

(Y)es / (N)o

(C)onfidentiality

(I)ntegrity

(A)vailability

RPN

(C+I+A)

(S)atisfactory

L1

M2

H3

L1

M2

H3

L1

M2

H3

(O)ther than satisfactory +##

 

 

 

 

 

 

 

 

 

 

 

 

###

ir-4

incident handling  

 

assessment objective:

Determine if the organization:

ir-4(a)    

implements an incident handling capability for security incidents that includes:

ir-4(a)[1]

preparation;

ir-4(a)[2]

detection and analysis;

ir-4(a)[3]

containment;

ir-4(a)[4]

eradication;

ir-4(a)[5]

recovery;

ir-4(b)    

coordinates incident handling activities with contingency planning activities;

ir-4(c)    

ir-4(c)[1]    

incorporates lessons learned from ongoing incident handling activities into:

ir-4(c)[1][a]  

incident response procedures;

ir-4(c)[1][b]    

training;

ir-4(c)[1][c]    

testing/exercises;

ir-4(c)[2]    

implements the resulting changes accordingly to:

ir-4(c)[2][a]  

incident response procedures;

ir-4(c)[2][b]    

training; and

ir-4(c)[2][c]    

testing/exercises.

potential assessment methods and objects:

Examine: [select from: Incident response policy; contingency planning policy; procedures addressing incident handling; incident response plan; contingency plan; security plan; other relevant documents or records].

Interview: [select from: Organizational personnel with incident handling responsibilities; organizational personnel with contingency planning responsibilities; organizational personnel with information security responsibilities].

Test: [select from: Incident handling capability for the organization].

Hosted by ABCI Consultants for Information Security Management Systems | Implementations, Training and Assessments for Compliance | (800) 644-2056