Implement policies to address security incidents. NIST recommends an incident response plan aligned to NIST SP 800-61 with detection, analysis, containment, eradication, and recovery phases.
What else in your programme already covers this
This control maps to 82 controls across 30 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST800-PM-16 Threat Awareness Program. Implement a threat awareness program that includes a cross-organization information-sharing capability for threat intelligence
NIST800-SI-5 Security alerts, advisories, and directives
6.4.1 For public-facing web applications, new threats and vulnerabilities are addressed on an ongoing basis and these applications are protected against known attacks as follows: • Reviewing public-facing web applications via manual or automated application
6.4.2 For public-facing web applications, an automated technical solution is deployed that continually detects and prevents web-based attacks, with at least the following: • Is installed in front of public-facing web applications and is configured
6.3.1 Security vulnerabilities are identified and managed as follows: • New security vulnerabilities are identified using industry-recognized sources for security vulnerability information, including alerts from international and national computer emergency response teams (CERTs). • Vulnerabilities
SOC2-CC7.1 Detection and monitoring procedures for security events are in place
SOC2-CC7.3 Evaluates security events to determine incident status
SOC2-CC7.4 Responds to identified security incidents through defined procedures
SOC2-CC7.5 Identifies the root cause of security incidents
SOC2-P6.3 Creates and retains a complete, accurate, and timely record of detected or reported unauthorized disclosures (including breaches) of personal information to meet the entity's objectives related to privacy. The following point of focus, which
You are reading one control. How much of HIPAA Security Rule have you already done?
HIPAA Security Rule 164.308(a)(6)(i) is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of HIPAA Security Rule your existing evidence covers. Hold ISO 27001:2022 and 53 of 67 HIPAA Security Rule controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 64 were rejected on the ISO 27001:2022 pair alone.