CMMC 1.0 Practice IR.2.094 Requirement:
Analyze and triage events to support event resolution and incident declaration.
CMMC 1.0 IR.2.094 Requirement Explanation:
By categorizing incidents you can efficiently respond to them and escalate them to the appropriate persons.
Example CMMC 1.0 IR.2.094 Implementation:
Establish incident categories, an example is the U.S. CERT's Federal Agency Incident Categories. When a security incident occurs categorize it so that you can respond to it appropriately. Use the assigned category to help prioritize incident response. Analyze incidents to determine if they are isolated or part of larger problem.
CMMC 1.0 IR.2.094 Scenario(s):
- Scenario 1:
Your company uses the U.S. CERT's Federal Agency Incident Categories to categorize security incidents. You discover malware installed on one of your systems and label it as a Category 3 incident. Because it is a category 3 incident it warrants an immediate response and must be reported to management within 1 hour. Your staff responds to the incident and analyzes it determining that the malware has only infect one machine. Your staff responds to and closes the incident and responds to it in accordance with your incident response plan.
Discover Our NIST SP 800-171 & CMMC 2.0 Solutions:
Power through compliance. Meet and maintain your NIST SP 800-171 & CMMC 2.0 compliance requirements.
Transform your business. Create new revenue streams and provide scalability for your NIST SP 800-171 and CMMC 2.0 services.
Supply Chain Verifier
Trust is everything. Verify, monitor, and support subcontactor compliance.