RS.AN-4.1: Information/cybersecurity incidents shall be categorized according to the level of severity and impact consistent with the evaluation criteria included the incident response plan.
It should be considered to determine the causes of an information/cybersecurity incident and implement a corrective action in order that the incident does not recur or occur elsewhere.
The effectiveness of any corrective action taken should be reviewed.
Corrective actions should be appropriate to the effects of the information/cybersecurity incident encountered.
Documentation Maturity
Implementation Maturity
Description
Information/cybersecurity incidents shall be categorized according to the level of severity and impact consistent with the evaluation criteria included the incident response plan.