CIS Controls v8
CIS Control 17: Incident Response Management

CIS Controls v8 CIS-17.9: Establish and Maintain Security Incident Thresholds

Set up and keep thresholds for security incidents that, as a minimum, distinguish an incident from an event. Examples may include unusual activity, a security vulnerability, a security weakness, a data breach and a privacy incident, among others. Review them each year, or sooner when a major change in the enterprise could affect this Safeguard.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 41 controls across 25 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 5 controls

APRA CPS 234 · 2 controls

  • CPS234-35 APRA Notification of Material Incidents within 72 Hours
  • CPS234-P24 Information Security Response Plans
  • ASBv3-IR-3 Detection and analysis - create incidents based on high-quality alerts
  • ASBv3-IR-5 Detection and analysis - prioritize incidents

DORA · 2 controls

  • DORA-Art.17 ICT-related incident management process
  • DORA-Art.18 Classification of ICT-related incidents and cyber threats

FedRAMP High · 2 controls

  • IR-1 Policy and Procedures
  • IR-8 Incident Response Plan

FedRAMP Moderate · 2 controls

  • IR-1 Policy and Procedures
  • IR-8 Incident Response Plan

ISO 22301:2019 · 2 controls

  • 8.4.2 Response structure
  • 9.1 Monitoring, measurement, analysis and evaluation

ISO 27002:2022 · 2 controls

  • 5.24 Information security incident management planning and preparation
  • 5.25 Assessment and decision on information security events

PCI DSS 4.0 · 2 controls

  • 12.10.1 12.10.1 Incident response plan ready for activation
  • 12.10.5 12.10.5 Plan covers alerts from security monitoring systems

SOC 2 · 2 controls

  • SOC2-CC7.3 CC7.3 Evaluating security events to identify incidents
  • SOC2-P6.6 P6.6 Notifying breaches and incidents
  • ANSSI-HYG-40 Define a Security Incident Management Procedure
  • CPS230-P33 APRA Notification of Operational Risk Incidents within 72 Hours
  • ISM-1228 Analysing cyber security events for incidents

C5 (Germany) · 1 control

  • C5-OPS-13 Logging and Monitoring - Identification of Events
  • CFTC-SS-16 Security Incident Response Plan and Testing

CIS Controls v8.1 · 1 control

  • 17.9 Establish and Maintain Security Incident Thresholds

CMMC 2.0 · 1 control

ISO 27001:2022 · 1 control

  • 5.25 Assessment and decision on information security events

ISO 27701:2019 · 1 control

  • 6.13.1 Management of information security incidents and improvements

NIS2 Directive · 1 control

NIST SP 800-172 · 1 control

  • 3.6.1e Establish Security Operations Center (SOC)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in CIS Control 17: Incident Response Management

You are reading one control. How much of CIS Controls v8 have you already done?

CIS Controls v8 CIS-17.9 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of CIS Controls v8 your existing evidence covers. Hold ISO 27001:2022 and 102 of 153 CIS Controls v8 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 240 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 41 it maps to, and the evidence behind each claim, over MCP and REST.