Requirement:
The requirements for cybersecurity incidents and threat management must be implemented.
Control Implementation Guidelines:
- Implement cybersecurity requirements to Cybersecurity Incident and Threat management, including, but not limited to, the following:
- Define a cybersecurity incident response plan
- Classify cybersecurity incidents by severity
- Define the roles and responsibilities for cybersecurity incident response and how to communicate with all stakeholders
- Define a mechanism for notifying the National Cybersecurity Authority in the event of a cybersecurity incident
- Share incidents notifications, threat intelligence, intrusion indicators and reports with NCA
- Collect and handle threat intelligence feeds
- Periodically review of cybersecurity incident response plan
Expected Deliverables:
- The approved cybersecurity incident response plan (electronic copy)
- A sample of a previous cybersecurity incident report
- Cybersecurity incidents classification mechanism based on severity
Quick & Simple
Discover Our Cybersecurity Compliance Solutions:
Whether you need to meet and maintain your compliance requirements, help your clients meet them, or verify supplier compliance we have the expertise and solution for you