C5 (Germany)
C5: Security Incident Management

C5 (Germany) C5-SIM-01: Policy for security incident management

Document, communicate and provide an incident response policy with technical and organisational safeguards for fast and proper handling, defining classification, prioritisation and escalation rules, interfaces to incident and continuity management, a standing computer emergency response team, and timely customer notification.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 54 controls across 29 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-DE.AE-08 Incidents are declared when adverse events meet the defined incident criteria
  • NIST-CSF-GV.SC-08 Relevant suppliers and other third parties are included in incident planning, response, and recovery activities
  • NIST-CSF-ID.IM-04 Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved
  • NIST-CSF-RS.MA-01 The incident response plan is executed in coordination with relevant third parties once an incident is declared
  • NIST-CSF-RS.MA-03 Incidents are categorized and prioritized
  • NIST-CSF-RS.MA-04 Incidents are escalated or elevated as needed

APRA CPS 234 · 3 controls

  • CPS234-32 Annual Review and Testing of Response Plans
  • CPS234-P24 Information Security Response Plans
  • CPS234-P25 Response Plan Content and Escalation Mechanisms

CIS Controls v8 · 3 controls

  • CIS-17.1 Designate Personnel to Manage Incident Handling
  • CIS-17.4 Establish and Maintain an Incident Response Process
  • CIS-17.5 Assign Key Roles and Responsibilities

NIST SP 800-161 Rev 1 · 3 controls

  • SEC10-BP01 Identify key personnel and external resources
  • SEC10-BP02 Develop incident management plans
  • ASBv3-GS-7 Define and implement logging, threat detection and incident response strategy
  • ASBv3-IR-1 Preparation - update incident response plan and handling process

FedRAMP High · 2 controls

  • IR-1 Policy and Procedures
  • IR-8 Incident Response Plan

FedRAMP Moderate · 2 controls

  • IR-1 Policy and Procedures
  • IR-8 Incident Response Plan

ISO 27701:2019 · 2 controls

  • 6.13.1 Management of information security incidents and improvements
  • 8.2.1 Customer agreement

NIS2 Directive · 2 controls

  • Art.21.2.b Incident handling
  • Art.23.1 Notify significant incidents to the CSIRT or competent authority, and warn affected service recipients

NIST SP 800-171 Rev 3 · 2 controls

NIST SP 800-172 · 2 controls

  • 3.6.1e Establish Security Operations Center (SOC)
  • 3.6.2e Establish and Maintain a Cyber Incident Response Team

NIST SP 800-53 Rev 5 · 2 controls

SOC 2 · 2 controls

  • SOC2-CC7.3 CC7.3 Evaluating security events to identify incidents
  • SOC2-CC7.4 CC7.4 Responding to security incidents
  • ANSSI-HYG-40 Define a Security Incident Management Procedure

APPI · 1 control

  • APPI-A26 Report of Leakage to the Commission and Notification to the Person

CMMC 2.0 · 1 control

DORA · 1 control

GDPR · 1 control

  • GDPR-Art.33 Notification of a personal data breach to the supervisory authority

HIPAA Security Rule · 1 control

ISO 22301:2019 · 1 control

ISO 27001:2022 · 1 control

  • 5.24 Information security incident management planning and preparation 

ISO 27002:2022 · 1 control

  • 5.24 Information security incident management planning and preparation

PCI DSS 4.0 · 1 control

  • 12.10.1 12.10.1 Incident response plan ready for activation

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in C5: Security Incident Management

You are reading one control. How much of C5 (Germany) have you already done?

C5 (Germany) C5-SIM-01 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of C5 (Germany) your existing evidence covers. Hold Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 and 95 of 121 C5 (Germany) controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 pair alone.

Query this from an agent

The graph holds this control, the 54 it maps to, and the evidence behind each claim, over MCP and REST.