CSF 2.0 outcome: information is shared with designated internal and external stakeholders. Priority High. N1: voluntary sharing is often mutually beneficial because the same threats hit many organizations at once, for example sharing observed TTPs with a sector ISAC. N2: sharing defensive tactics improves situational awareness and resilience and raises attackers' costs. N3: handlers may coordinate with peers at partner organizations to share tactical technical information on an attack spanning them, and may pool resources. R1: share information securely, consistent with response plans and information sharing agreements, including contracts with suppliers. R2: update senior leadership regularly on major incidents. R3: notify human resources when malicious insider activity has occurred. R4: set and follow media communication procedures for incident response that comply with the organization's policies on media interaction and disclosure.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.