Show/Hide Toolbars

ABCI Consultants

Guidance for NIST 800-171 Assessment & Compliance

Navigation: IR-FAMILY: INCIDENT RESPONSE

IR-6(3) INCIDENT REPORTING  |  COORDINATION WITH SUPPLY CHAIN

Scroll Prev Top Next More

Applicable

(Y)es / (N)o

(C)onfidentiality

(I)ntegrity

(A)vailability

RPN

(C+I+A)

(S)atisfactory

L1

M2

H3

L1

M2

H3

L1

M2

H3

(O)ther than satisfactory +##

 

 

 

 

 

 

 

 

 

 

 

 

###

ir-6(3)

incident reporting  | coordination with supply chain

 

assessment objective:

Determine if the organization provides security incident information to other organizations involved in the supply chain for information systems or information system components related to the incident.

potential assessment methods and objects:

Examine: [select from: Incident response policy; procedures addressing supply chain coordination; acquisition contracts; service-level agreements; incident response plan; security plan; plans of other organization involved in supply chain activities; other relevant documents or records].

Interview: [select from: Organizational personnel with incident reporting responsibilities; organizational personnel with information security responsibilities; organizational personnel with supply chain responsibilities].

Test: [select from: Organizational processes for incident reporting; automated mechanisms supporting and/or implementing reporting of incident information involved in the supply chain].

Hosted by ABCI Consultants for Information Security Management Systems | Implementations, Training and Assessments for Compliance | (800) 644-2056