Frameworks / ANSSI Guide d'hygiene informatique (42 mesures, v2.0) / ANSSI-HYG-40 ANSSI Guide d'hygiene informatique (42 mesures, v2.0)
ANSSI Hygiene IX: Supervise, Audit and Respond (measures 36 to 40)
ANSSI Guide d'hygiene informatique (42 mesures, v2.0) ANSSI-HYG-40: Define a Security Incident Management Procedure Define a procedure for managing security incidents, covering how they are reported, handled and closed.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 73 controls across 26 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-DE.AE-08 Incidents are declared when adverse events meet the defined incident criteria NIST-CSF-ID.IM-03 Improvements are identified from execution of operational processes, procedures, and activities NIST-CSF-ID.IM-04 Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved NIST-CSF-RS.CO-02 Internal and external stakeholders are notified of incidents NIST-CSF-RS.MA-01 The incident response plan is executed in coordination with relevant third parties once an incident is declared NIST-CSF-RS.MA-02 Incident reports are triaged and validated NIST-CSF-RS.MA-03 Incidents are categorized and prioritized CIS-17.3 Establish and Maintain an Enterprise Process for Reporting Incidents CIS-17.4 Establish and Maintain an Incident Response Process CIS-17.5 Assign Key Roles and Responsibilities CIS-17.8 Conduct Post-Incident Reviews CIS-17.9 Establish and Maintain Security Incident Thresholds 5.24 Information security incident management planning and preparation 5.25 Assessment and decision on information security events 5.26 Response to information security incidents 6.8 Information security event reporting 5.24 Information security incident management planning and preparation 5.25 Assessment and decision on information security events 5.26 Response to information security incidents 6.8 Information security event reporting 12.10.1 12.10.1 Incident response plan ready for activation 12.10.2 12.10.2 Annual review and testing of the incident response plan 12.10.5 12.10.5 Plan covers alerts from security monitoring systems 12.10.6 12.10.6 Plan evolved from lessons learned and industry developments CPS234-30 Detection and Response Mechanisms CPS234-P24 Information Security Response Plans CPS234-P25 Response Plan Content and Escalation Mechanisms SEC10-BP02 Develop incident management plans SEC10-BP04 Develop and test security incident response playbooks SEC10-BP08 Establish a framework for learning from incidents C5-SIM-01 Policy for security incident management C5-SIM-02 Processing of security incidents C5-SIM-03 Documentation and reporting of security incidents IR-4 Incident Handling IR-6 Incident Reporting IR-8 Incident Response Plan IR-4 Incident Handling IR-6 Incident Reporting IR-8 Incident Response Plan 03.06.01 Incident Handling 03.06.02 Incident Monitoring, Reporting, and Response Assistance 03.06.05 Incident Response Plan E8-ADMIN-ML2 Restrict Administrative Privileges (ML2) E8-APP-ML2 Application Control (ML2) ASD37-28 Continuous incident detection and response (Excellent) ASD37-35 Business continuity and disaster recovery plans (Very Good) ASBv3-IR-1 Preparation - update incident response plan and handling process ASBv3-IR-2 Preparation - setup incident notification SOC2-CC7.3 CC7.3 Evaluating security events to identify incidents SOC2-CC7.4 CC7.4 Responding to security incidents APPI-A26 Report of Leakage to the Commission and Notification to the Person CPS230-27 Identification and Escalation of Incidents and Near Misses A.8.4 Communication of incidents 3.6.2e Establish and Maintain a Cyber Incident Response Team CE-SC.8 Process for Compromised Passwords Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in ANSSI Hygiene IX: Supervise, Audit and Respond (measures 36 to 40) You are reading one control. How much of ANSSI Guide d'hygiene informatique (42 mesures, v2.0) have you already done? ANSSI Guide d'hygiene informatique (42 mesures, v2.0) ANSSI-HYG-40 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ANSSI Guide d'hygiene informatique (42 mesures, v2.0) your existing evidence covers. Hold FedRAMP Moderate and 35 of 42 ANSSI Guide d'hygiene informatique (42 mesures, v2.0) controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the FedRAMP Moderate pair alone.
Query this from an agent The graph holds this control, the 73 it maps to, and the evidence behind each claim, over MCP and REST.