The organisation develops, documents and disseminates to defined personnel or roles a incident response policy at the selected organisation, business process and, or, system level that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organisational entities and compliance and is consistent with applicable laws, Orders in Council, jurisprudence, directives, regulations, policies, standards and guidelines, together with procedures to implement the policy and the associated incident response controls; designates an official to manage the policy and procedures; and reviews and updates the policy and the procedures at a set frequency and after defined events. The GC discussion requires incident response policy and procedures to build in heightened readiness during emergencies and heightened cyber threat, per the TBS mandatory procedures for security event management and IT security control. No enhancements.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.