CMMC 1.0 Practice IR.2.094 Requirement:
Analyze and triage events to support event resolution and incident declaration.
CMMC 1.0 IR.2.094 Requirement Explanation:
By categorizing incidents you can efficiently respond to them and escalate them to the appropriate persons.
Example CMMC 1.0 IR.2.094 Implementation:
Establish incident categories, an example is the U.S. CERT's Federal Agency Incident Categories. When a security incident occurs categorize it so that you can respond to it appropriately. Use the assigned category to help prioritize incident response. Analyze incidents to determine if they are isolated or part of larger problem.
CMMC 1.0 IR.2.094 Scenario(s):
- Scenario 1:
Your company uses the U.S. CERT's Federal Agency Incident Categories to categorize security incidents. You discover malware installed on one of your systems and label it as a Category 3 incident. Because it is a category 3 incident it warrants an immediate response and must be reported to management within 1 hour. Your staff responds to the incident and analyzes it determining that the malware has only infect one machine. Your staff responds to and closes the incident and responds to it in accordance with your incident response plan.
Quick & Simple
Discover Our Cybersecurity Compliance Solutions:
Whether you need to meet and maintain your compliance requirements, help your clients meet them, or verify supplier compliance we have the expertise and solution for you