MTCS (Singapore)
11: Incident management – MTCS (Singapore)

MTCS (Singapore) 11.2: Information security incident response plan and procedures

Incident response plan and procedures. Level 1 (a to i): roles and responsibilities of the CSP and parties supporting the service; procedures for contacting and communicating with parties inside and outside the organization when a breach occurs; the extent of cooperation defined in the SLA; root cause and impact analysis with follow-up; response, escalation and recovery procedures with resolution timeframes; monitoring and quantifying incidents by type, volume and cost; classification of incidents by severity with prioritisation; disclosure of breaches to potentially affected customers; and the ability to provide customers with digital forensic evidence. Level 2 (a to e): designated staff available to respond to alerts from intrusion detection, prevention and file-integrity monitoring; compliance with legal breach reporting; tracking every incident to closure; escalation, containment and remediation; and identification and notification of affected customers with the planned remediation. Level 3 (a to d): a formal strategy against botnets and DDoS, a prepared public relations plan, advance reporting to affected customers on major incidents, and forensic procedures for collecting, retaining and presenting evidence.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27002:2022 · 1 control

  • 5.24 Information security incident management planning and preparation

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in 11: Incident management – MTCS (Singapore)

Query this from an agent

The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.