HomeControl Library › 3.6.1
3.6 Incident Response5 pts

3.6.1 — Have an incident-response capability

Establish an operational incident-handling capability for organizational systems that includes preparation, detection, analysis, containment, recovery, and user response activities.

You can prepare for, detect, contain, and recover from incidents.

What it actually means

A working incident-response capability — a documented plan plus the means to actually run it: prepare, detect, analyze, contain, recover, and handle user response. Not just a binder; an ability you could exercise if something happened tonight.

Pass or fail — an assessor needs a "yes" to each

What to have ready

Where teams trip up

See where this control puts your score

Run all 110 requirements free in about 10 minutes.

Calculate your SPRS score →

Connected requirements

← Back to the Control Library