Incident management (RS.MA)
In this control family, we will need to create an IR plan. This plan will encompass several aspects of how to respond to an incident. We will need to write policies and procedures for how to discover an incident, determine the threat level, and respond accordingly.
RS.MA-01
Throughout the last few chapters, we have discussed the need to work with vendors and trusted third parties when an incident occurs. If you have outsourced security services to a Managed Service Provider (MSP), then you should work with them to develop an IR playbook. This playbook will be executed when an incident is declared.
The playbook is a step-by-step procedure for how to handle a given situation. For example, if you experience an account takeover scenario, then there are steps that you should take to minimize the risks associated. Many playbooks are created...