Sekit CSF · Family
Incident Response
21 controls in 7 topics, each seen through the policy, process and technical lenses.
Policy
RCF-0268Forensics readiness3 mappingsThe company has a formal approach to preserving evidence when a security incident occursRCF-0259IR plan3 mappingsThe company has a formal plan defining how to respond to security incidentsRCF-0271Notification & escalation5 mappingsFormal procedures define who must be notified and within what timeframes when an incident occursRCF-0265Playbooks5 mappingsStep-by-step response procedures exist for the most likely incident scenariosRCF-0277Post-incident review (lessons learned)4 mappingsIncidents are formally reviewed after resolution to identify improvementsRCF-0262Roles & communications5 mappingsSecurity roles and responsibilities during an incident are formally defined and documentedRCF-0274Tabletop exercises4 mappingsThe company formally plans and conducts simulated incident exercises on a regular basis
Process
RCF-0269Forensics readiness2 mappingsEvidence is consistently preserved and chain of custody maintained during incident investigationRCF-0260IR plan4 mappingsThe incident response plan is consistently followed when incidents occurRCF-0272Notification & escalation5 mappingsNotifications to regulators, clients and leadership are sent consistently within required timeframesRCF-0266Playbooks6 mappingsPlaybooks are consistently followed during incidents and kept current with lessons learnedRCF-0278Post-incident review (lessons learned)4 mappingsPost-incident lessons are consistently implemented to prevent recurrenceRCF-0263Roles & communications5 mappingsIncident roles are consistently activated and team members know their responsibilities when an incident occursRCF-0275Tabletop exercises4 mappingsTabletop exercises are conducted regularly and findings are used to improve the response plan
Technical
RCF-0270Forensics readiness3 mappingsTechnical controls capture and preserve forensic evidence automatically when incidents are detectedRCF-0261IR plan5 mappingsTechnical tools support automated detection and response to incidentsRCF-0273Notification & escalation4 mappingsTechnical systems support automated notification workflows and track notification deadlinesRCF-0267Playbooks5 mappingsTechnical tools execute or guide playbook steps automatically during incident responseRCF-0279Post-incident review (lessons learned)5 mappingsTechnical tools capture incident data to support post-incident analysisRCF-0264Roles & communications4 mappingsTechnical tools support team coordination and communication during incident responseRCF-0276Tabletop exercises4 mappingsTechnical tools support realistic simulation of incident scenarios for training purposes
This family in ISO/IEC 27001:2022
Every framework item the family's controls map to, most-connected first — grouped by Sekit CSF family, never by the framework's own index.
This family in NIST CSF 2.0
This family in ISO/IEC 42001:2023 — Annex A
Ask Sekura: “What evidence proves Incident Response?”
Also via MCP, free with account