PlumbTrackLive demoGRC Risk System

← internal audit

Audit — IR-6 — Incident Reporting

Framework: NIST SP 800-53 Rev.5 IR-6 · Mark each check Pass / Fail / N/A; a Fail is a finding to remediate. · open the item

0 pass · 0 finding(s) · 0 N/A · 0 of 7 checked
Examine Examine the incident reporting policy/procedure to confirm it defines the specific time period within which personnel must report a suspected incident to the organizational incident response capability.
Interview Interview a sample of general (non-IR) staff to confirm they know how to report a suspected incident and the timeframe for doing so (CIS Controls v8 17.3 designated reporting mechanism known to the workforce).
Examine Examine a sample of incident records to verify reports were submitted within the required timeframe and contain the required data elements (who, what, when, affected systems, indicators).
Examine Examine records confirming that qualifying incidents were reported to the designated external authorities and organizations (e.g., CISA/US-CERT, regulators, law enforcement, contractual parties) as required.
Test Test the reporting channel (hotline, ticketing portal, or monitored mailbox) by submitting a test report and confirming it reaches the incident response team and generates a tracked case.
Examine Examine configuration/evidence that incident reporting is automated where required (IR-6(1)), for example SIEM/SOAR alerts routing detected events to the incident response team.
Interview Interview the incident response lead to confirm the process for reporting incident-related vulnerabilities and supply-chain incidents to affected internal owners and external stakeholders (IR-6(2)/IR-6(3)).