Sekit CSF · Familia
Incident Response
21 controles en 7 temas, cada uno visto a través de las lentes de política, proceso y técnica.
Política
RCF-0268Forensics readiness3 mapeosThe company has a formal approach to preserving evidence when a security incident occursRCF-0259IR plan3 mapeosThe company has a formal plan defining how to respond to security incidentsRCF-0271Notification & escalation5 mapeosFormal procedures define who must be notified and within what timeframes when an incident occursRCF-0265Playbooks5 mapeosStep-by-step response procedures exist for the most likely incident scenariosRCF-0277Post-incident review (lessons learned)4 mapeosIncidents are formally reviewed after resolution to identify improvementsRCF-0262Roles & communications5 mapeosSecurity roles and responsibilities during an incident are formally defined and documentedRCF-0274Tabletop exercises4 mapeosThe company formally plans and conducts simulated incident exercises on a regular basis
Proceso
RCF-0269Forensics readiness2 mapeosEvidence is consistently preserved and chain of custody maintained during incident investigationRCF-0260IR plan4 mapeosThe incident response plan is consistently followed when incidents occurRCF-0272Notification & escalation5 mapeosNotifications to regulators, clients and leadership are sent consistently within required timeframesRCF-0266Playbooks6 mapeosPlaybooks are consistently followed during incidents and kept current with lessons learnedRCF-0278Post-incident review (lessons learned)4 mapeosPost-incident lessons are consistently implemented to prevent recurrenceRCF-0263Roles & communications5 mapeosIncident roles are consistently activated and team members know their responsibilities when an incident occursRCF-0275Tabletop exercises4 mapeosTabletop exercises are conducted regularly and findings are used to improve the response plan
Técnica
RCF-0270Forensics readiness3 mapeosTechnical controls capture and preserve forensic evidence automatically when incidents are detectedRCF-0261IR plan5 mapeosTechnical tools support automated detection and response to incidentsRCF-0273Notification & escalation4 mapeosTechnical systems support automated notification workflows and track notification deadlinesRCF-0267Playbooks5 mapeosTechnical tools execute or guide playbook steps automatically during incident responseRCF-0279Post-incident review (lessons learned)5 mapeosTechnical tools capture incident data to support post-incident analysisRCF-0264Roles & communications4 mapeosTechnical tools support team coordination and communication during incident responseRCF-0276Tabletop exercises4 mapeosTechnical tools support realistic simulation of incident scenarios for training purposes
Esta familia en ISO/IEC 27001:2022
Cada elemento de marco al que mapean los controles de la familia, primero los más conectados; agrupado por familia del Sekit CSF, nunca por el índice del propio marco.
Esta familia en NIST CSF 2.0
Esta familia en ISO/IEC 42001:2023 — Annex A
Pregúntale a Sekura: «¿Qué evidencia demuestra Incident Response?»
También vía MCP, gratis con cuenta