CSF 2.0 outcome: internal and external stakeholders are notified of incidents. Priority High. R1: once an incident is analyzed and prioritized, the team should coordinate with the right people inside and outside the organization so all who need to be involved play their roles. R2: follow established coordination procedures that say what must be reported to whom and when (initial notification, regular status updates). R3: notify in compliance with the current incident notification laws and regulations applying to the organization's sectors, locations, customer locations and other characteristics, a field where new laws appear frequently. R4: notify affected third parties of data breaches and other incidents under regulatory, legal and contractual requirements. R5: notify law enforcement and regulators on the criteria in the incident response plan and with management approval, through designated individuals acting consistently with the law and the organization's policies and procedures.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.