When malicious code is detected, agencies should: isolate the infected system; decide whether to ask the NCSC for help; if help is requested and agreed, hold off any further action until the NCSC advises; check connected systems and media, backups included, for malicious code; isolate every infected system and item of media so reinfection cannot occur; change every password and all key material held on, or possibly accessed from, compromised systems, including those for websites with password-controlled access; tell system users about relevant aspects of the compromise, including advice that they change every password on the compromised systems; revoke every session token tied to the user and/or device; remove the malware from systems or media with up-to-date anti-malware software; watch network traffic for signs of malicious activity; record the incident, report it, and carry out any other activities the IRP specifies; and, in some scenarios, rebuild and reinitialise the system and/or user profile where required.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.