Azure Security Benchmark
Incident Response

Azure Security Benchmark ASBv3-IR-2: Preparation - setup incident notification

Set up incident notification so security alerts from the cloud platform and from the environment reach the correct contact in the incident response organisation.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 49 controls across 25 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

FedRAMP High · 4 controls

  • IR-6 Incident Reporting
  • IR-6(1) Automated Reporting
  • SI-4(5) System-Generated Alerts
  • SI-5 Security Alerts, Advisories, and Directives

FedRAMP Moderate · 4 controls

  • IR-6 Incident Reporting
  • IR-6(1) Automated Reporting
  • SI-4(5) System-Generated Alerts
  • SI-5 Security Alerts, Advisories, and Directives

CIS Controls v8 · 3 controls

  • CIS-17.2 Establish and Maintain Contact Information for Reporting Security Incidents
  • CIS-17.3 Establish and Maintain an Enterprise Process for Reporting Incidents
  • CIS-17.6 Define Mechanisms for Communicating During Incident Response

ISO 27002:2022 · 3 controls

  • 5.24 Information security incident management planning and preparation
  • 5.25 Assessment and decision on information security events
  • 6.8 Information security event reporting

C5 (Germany) · 2 controls

  • C5-OPS-21 Involvement of Cloud Customers in the Event of Incidents
  • C5-SIM-04 Duty of the users to report security incidents to a central body

CMMC 2.0 · 2 controls

ISO 27001:2022 · 2 controls

  • 5.24 Information security incident management planning and preparation 
  • 6.8 Information security event reporting

NIST SP 800-161 Rev 1 · 2 controls

NIST SP 800-171 Rev 3 · 2 controls

  • 03.06.02 Incident Monitoring, Reporting, and Response Assistance
  • 03.14.03 Security Alerts, Advisories, and Directives

NIST SP 800-172 · 2 controls

  • 3.6.1e Establish Security Operations Center (SOC)
  • 3.6.2e Establish and Maintain a Cyber Incident Response Team

NIST SP 800-53 Rev 5 · 2 controls

PCI DSS 4.0 · 2 controls

  • 12.10.3 12.10.3 Incident response personnel available 24/7
  • 12.10.5 12.10.5 Plan covers alerts from security monitoring systems

SOC 2 · 2 controls

  • SOC2-CC7.3 CC7.3 Evaluating security events to identify incidents
  • SOC2-CC7.4 CC7.4 Responding to security incidents
  • E8-ADMIN-ML2 Restrict Administrative Privileges (ML2)
  • ANSSI-HYG-40 Define a Security Incident Management Procedure

APRA CPS 234 · 1 control

  • CPS234-P25 Response Plan Content and Escalation Mechanisms
  • SEC10-BP01 Identify key personnel and external resources

HIPAA Security Rule · 1 control

ISO 22301:2019 · 1 control

  • 8.4.3 Warning and communication

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Incident Response

You are reading one control. How much of Azure Security Benchmark have you already done?

Azure Security Benchmark ASBv3-IR-2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of Azure Security Benchmark your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 71 of 85 Azure Security Benchmark controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 49 it maps to, and the evidence behind each claim, over MCP and REST.