Essential Cybersecurity Controls (ECC – 2 : 2024) - 2-13-1

Requirements For Cybersecurity Incidents And Threat Management Must Be Defined, Documented And Approved.

Essential Cybersecurity Controls (ECC – 2 : 2024) - 2-13-2

The Requirements For Cybersecurity Incidents And Threat Management Must Be Implemented.

Essential Cybersecurity Controls (ECC – 2 : 2024) - 2-13-3

  1. The requirements for cybersecurity incidents and threat management must include at least the following:
    1. Cybersecurity incident response plans and escalation procedures.
    2. Cybersecurity incidents classification.
    3. Cybersecurity incidents reporting to NCA
    4. Sharing incidents notifications, threat intelligence, breach indicators and reports with NCA.
    5. Collecting and handling threat intelligence feeds.

Essential Cybersecurity Controls (ECC – 2 : 2024) - 2-13-4

The Requirements For Cybersecurity Incidents And Threat Management Must Be Reviewed Periodically.