Sekit CSF · Familia
Incident Response
21 controles en 7 temas, cada uno visto a través de las lentes de política, proceso y técnica.
Política
RCF-0268Forensics readinesssin mapeos aúnThe company has a formal approach to preserving evidence when a security incident occursRCF-0259IR plansin mapeos aúnThe company has a formal plan defining how to respond to security incidentsRCF-0271Notification & escalationsin mapeos aúnFormal procedures define who must be notified and within what timeframes when an incident occursRCF-0265Playbookssin mapeos aúnStep-by-step response procedures exist for the most likely incident scenariosRCF-0277Post-incident review (lessons learned)sin mapeos aúnIncidents are formally reviewed after resolution to identify improvementsRCF-0262Roles & communicationssin mapeos aúnSecurity roles and responsibilities during an incident are formally defined and documentedRCF-0274Tabletop exercisessin mapeos aúnThe company formally plans and conducts simulated incident exercises on a regular basis
Proceso
RCF-0269Forensics readinesssin mapeos aúnEvidence is consistently preserved and chain of custody maintained during incident investigationRCF-0260IR plansin mapeos aúnThe incident response plan is consistently followed when incidents occurRCF-0272Notification & escalationsin mapeos aúnNotifications to regulators, clients and leadership are sent consistently within required timeframesRCF-0266Playbookssin mapeos aúnPlaybooks are consistently followed during incidents and kept current with lessons learnedRCF-0278Post-incident review (lessons learned)sin mapeos aúnPost-incident lessons are consistently implemented to prevent recurrenceRCF-0263Roles & communicationssin mapeos aúnIncident roles are consistently activated and team members know their responsibilities when an incident occursRCF-0275Tabletop exercisessin mapeos aúnTabletop exercises are conducted regularly and findings are used to improve the response plan
Técnica
RCF-0270Forensics readinesssin mapeos aúnTechnical controls capture and preserve forensic evidence automatically when incidents are detectedRCF-0261IR plansin mapeos aúnTechnical tools support automated detection and response to incidentsRCF-0273Notification & escalationsin mapeos aúnTechnical systems support automated notification workflows and track notification deadlinesRCF-0267Playbookssin mapeos aúnTechnical tools execute or guide playbook steps automatically during incident responseRCF-0279Post-incident review (lessons learned)sin mapeos aúnTechnical tools capture incident data to support post-incident analysisRCF-0264Roles & communicationssin mapeos aúnTechnical tools support team coordination and communication during incident responseRCF-0276Tabletop exercisessin mapeos aúnTechnical tools support realistic simulation of incident scenarios for training purposes
Pregúntale a Sekura: «¿Qué evidencia demuestra Incident Response?»
Conecta tu IA · MCP gratis
https://staging.sekit.ai/api/mcp/crosswalk- En Claude o ChatGPT, añade un conector personalizado y pega esta URL.
- Inicia sesión con tu correo para terminar. Gratis, de solo lectura, sin necesidad de organización.