Develop and maintain Cyber Security Incident response plan per CIP-008-6 including: process for identifying + classifying + responding to + reporting reportable Cyber Security Incidents within 1 hour to E-ISAC and DHS CISA per EOP-004 + lessons learned within 90 days + testing at least every 15 months + update plan within 60 days of plan testing. Develop and maintain BES Cyber System Recovery Plan per CIP-009-6 including: backup and restoration + recovery testing at least every 15 months + plan review + plan updates within 60 days of testing + Information Verification for backup media.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.