ISO 27002:2022 5.26: Response to information security incidents
Incidents are to be handled following the documented response procedures. Purpose: respond to information security incidents efficiently and effectively. Guidance: set and communicate response procedures to relevant parties, and have a designated, competent team respond (5.24). Response includes: containing affected systems where consequences could spread; collecting evidence as early as possible (5.28); escalating as needed, including crisis management and possibly business continuity plans (5.29, 5.30); logging all response activity for later analysis; informing relevant internal and external parties of the incident or relevant details on a need-to-know basis; working with authorities, specialist groups, suppliers and clients to respond better and limit harm to others; formally closing and recording the incident once resolved; carrying out forensic analysis where required (5.28); analysing afterwards to find the root cause and documenting and communicating it as defined (5.27); and identifying and managing vulnerabilities and weaknesses, including control weaknesses that caused, contributed to or failed to stop the incident. More on incident handling is in ISO/IEC 27035.
This control maps to 144 controls across 43 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-DE.AE-06 Information on adverse events is provided to authorized staff and tools
NIST-CSF-ID.RA-06 Risk responses are chosen, prioritized, planned, tracked, and communicated
NIST-CSF-RC.CO-03 Recovery activities and progress in restoring operational capabilities are communicated to designated internal and external stakeholders
NIST-CSF-RC.CO-04 Public updates on incident recovery are shared using approved methods and messaging
NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process
NIST-CSF-RC.RP-06 The end of incident recovery is declared based on criteria, and incident-related documentation is completed
NIST-CSF-RS.AN-03 Analysis is performed to establish what has taken place during an incident and the root cause of the incident
NIST-CSF-RS.AN-08 An incident's magnitude is estimated and validated
NIST-CSF-RS.CO-02 Internal and external stakeholders are notified of incidents
NIST-CSF-RS.CO-03 Information is shared with designated internal and external stakeholders
NIST-CSF-RS.MA-01 The incident response plan is executed in coordination with relevant third parties once an incident is declared
E8-ADMIN-ISM-1819 Restrict administrative privileges (ISM-1819): Following the identification of a cyber security incident, the cyber security incident response plan is enacted
E8-APP-ISM-1819 Application control (ISM-1819): Following the identification of a cyber security incident, the cyber security incident response plan is enacted
E8-MFA-ISM-1819 Multi-factor authentication (ISM-1819): Following the identification of a cyber security incident, the cyber security incident response plan is enacted
E8-UAH-ISM-1819 User application hardening (ISM-1819): Following the identification of a cyber security incident, the cyber security incident response plan is enacted
You are reading one control. How much of ISO 27002:2022 have you already done?
ISO 27002:2022 5.26 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.