RS.AN-2.1: Thorough investigation and result analysis shall be the base for understanding the full implication of the information/cybersecurity incident.
Result analysis can involve the outcome of determining the correlation between the information of the detected event and the outcome of risk assessments. In this way, insight is gained into the impact of the event across the organization.
Consider including detection of unauthorized changes to its critical systems in its incident response capabilities.
Documentation Maturity
Implementation Maturity
Description
Thorough investigation and result analysis shall be the base for understanding the full implication of the information/cybersecurity incident.
RS.AN-2.2
RS.AN-2.2: The organization shall implement automated mechanisms to support incident impact analysis.
Implementation could vary from a ticketing system to a Security Information and Event Management (SIEM).
Documentation Maturity
Implementation Maturity
Description
The organization shall implement automated mechanisms to support incident impact analysis.