Establish a Computer Security Incident Response Team (CSIRT) per NIST SP 800-61 Rev 2 Section 2.4 (Incident Response Team Structure) and Section 2.5 (Incident Response Personnel). Team structure options include central team + distributed teams + coordinating team + fully-outsourced + partially-outsourced. Staffing model and selection considerations include team size + skills required (technical + communication + leadership + analytical) + multi-disciplinary coverage (network + system + application + forensic + legal + communications + privacy) + 24x7 coverage requirements + on-call rotation + escalation contacts. Define team relationships with the rest of the organisation: Management + Information Security + IT Support + Legal + Public Affairs and Media Relations + Human Resources + Business Continuity + Physical Security and Facilities Management. Establish formal handoff and information sharing channels with internal stakeholders and external coordinating bodies (sector ISAC + national CSIRT + law enforcement).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.