PlumbTrackLive demoGRC Risk System

← internal audit

Audit — IR-8 — Incident Response Plan

Framework: NIST SP 800-53 Rev.5 IR-8 · Mark each check Pass / Fail / N/A; a Fail is a finding to remediate. · open the item

0 pass · 0 finding(s) · 0 N/A · 0 of 7 checked
Examine Examine the incident response plan to confirm it contains all required elements: a roadmap for the IR capability, the structure/organization of the capability, the high-level approach, definitions of reportable incidents, metrics, required resources and management support, and provisions for sharing incident information.
Examine Examine the plan's approval/sign-off record to verify it was reviewed and approved by the designated personnel or senior leadership.
Examine Examine version history and review records to confirm the plan is reviewed and updated on the defined frequency and after significant organizational or system changes or problems encountered during execution.
Interview Interview incident response personnel to confirm they have received the current copy of the plan and understand their assigned roles and responsibilities (CIS Controls v8 17.1 designate personnel to manage incident handling).
Examine Examine distribution records and access controls to confirm the plan is distributed only to the defined list of roles and is protected from unauthorized disclosure and modification.
Examine Examine the plan to confirm it defines metrics for measuring the incident response capability and identifies the resources and management commitment needed to maintain it.
Interview Interview management to confirm the plan addresses coordination and information sharing with external stakeholders (e.g., partners, supply-chain entities, authorities).