IR-4(4)—Incident Handling
PBMM (P2)
Secret (P2)
Operational
>Control Description
INCIDENT HANDLING | INFORMATION CORRELATION The organization correlates incident information and individual incident responses to achieve an organization-wide perspective on incident awareness and response.
>Supplemental Guidance
Sometimes the nature of a threat event, for example, a hostile cyber-attack, is such that it can only be observed by bringing together information from different sources including various reports and reporting procedures established by organizations.
>Tailoring Guidance
Control enhancement (4) ensures that incident information and individual incident responses are stored centrally in order that they can be leveraged by the entire organization. This control enhancement can be implemented as simply as using a shared network folder for the storage of incident response information.
Ask AI
Configure your API key to use AI features.