Sekit CSF · Family
Incident Response
21 controls in 7 topics, each seen through the policy, process and technical lenses.
Policy
RCF-0268Forensics readinessno mappings yetThe company has a formal approach to preserving evidence when a security incident occursRCF-0259IR planno mappings yetThe company has a formal plan defining how to respond to security incidentsRCF-0271Notification & escalationno mappings yetFormal procedures define who must be notified and within what timeframes when an incident occursRCF-0265Playbooksno mappings yetStep-by-step response procedures exist for the most likely incident scenariosRCF-0277Post-incident review (lessons learned)no mappings yetIncidents are formally reviewed after resolution to identify improvementsRCF-0262Roles & communicationsno mappings yetSecurity roles and responsibilities during an incident are formally defined and documentedRCF-0274Tabletop exercisesno mappings yetThe company formally plans and conducts simulated incident exercises on a regular basis
Process
RCF-0269Forensics readinessno mappings yetEvidence is consistently preserved and chain of custody maintained during incident investigationRCF-0260IR planno mappings yetThe incident response plan is consistently followed when incidents occurRCF-0272Notification & escalationno mappings yetNotifications to regulators, clients and leadership are sent consistently within required timeframesRCF-0266Playbooksno mappings yetPlaybooks are consistently followed during incidents and kept current with lessons learnedRCF-0278Post-incident review (lessons learned)no mappings yetPost-incident lessons are consistently implemented to prevent recurrenceRCF-0263Roles & communicationsno mappings yetIncident roles are consistently activated and team members know their responsibilities when an incident occursRCF-0275Tabletop exercisesno mappings yetTabletop exercises are conducted regularly and findings are used to improve the response plan
Technical
RCF-0270Forensics readinessno mappings yetTechnical controls capture and preserve forensic evidence automatically when incidents are detectedRCF-0261IR planno mappings yetTechnical tools support automated detection and response to incidentsRCF-0273Notification & escalationno mappings yetTechnical systems support automated notification workflows and track notification deadlinesRCF-0267Playbooksno mappings yetTechnical tools execute or guide playbook steps automatically during incident responseRCF-0279Post-incident review (lessons learned)no mappings yetTechnical tools capture incident data to support post-incident analysisRCF-0264Roles & communicationsno mappings yetTechnical tools support team coordination and communication during incident responseRCF-0276Tabletop exercisesno mappings yetTechnical tools support realistic simulation of incident scenarios for training purposes
Ask Sekura: “What evidence proves Incident Response?”
Connect your AI · free MCP
https://staging.sekit.ai/api/mcp/crosswalk- In Claude or ChatGPT, add a custom connector and paste this URL.
- Sign in with your email to finish. Free, read-only, no organization required.