Processes, procedures, and technical measures should be defined and implemented to support the investigation and evaluation of security-related events that allow the organization to prioritize events by severity and impact. The objective for these measures is to prioritize the timely analysis of event information and rapid engagement of the incident response process.
Methodologies—including processes, tools, or machine learning algorithms used in incident handling—should periodically be reviewed for efficacy and accuracy in the current operating environment.
Define, implement and evaluate processes, procedures and technical measures supporting business processes to triage security-related events.