PlumbTrackLive demoGRC Risk System

← internal audit

Audit — IR-4 — Incident Handling

Framework: NIST SP 800-53 Rev.5 IR-4 · Mark each check Pass / Fail / N/A; a Fail is a finding to remediate. · open the item

0 pass · 0 finding(s) · 0 N/A · 0 of 7 checked
Examine Examine the incident handling procedures to confirm they document all lifecycle phases the control requires: preparation, detection and analysis, containment, eradication, and recovery (aligns with CIS Controls v8 17.4 established incident handling process).
Examine Examine a sample of closed incident records to verify each phase was actually executed and evidenced for that incident (e.g., recorded containment actions, eradication steps, and confirmed recovery/return-to-service).
Interview Interview incident responders to confirm they understand their assigned roles and the defined criteria for classifying and prioritizing incident severity/category.
Test Test the incident handling capability through a tabletop or simulated incident and observe whether responders progress from detection through recovery and meet defined response timeframes.
Examine Examine records showing that lessons learned from prior incidents were captured and fed back into updates to incident response procedures, training, and testing (CIS Controls v8 17.8 post-incident reviews).
Examine Examine documentation confirming incident handling activities are coordinated with contingency planning / business continuity and disaster recovery activities.
Interview Interview the incident response manager to confirm that response actions such as host isolation, blocking of malicious indicators, or dynamic reconfiguration are pre-authorized and available for use during an active incident.