Processes for reporting information security events related to offered cloud services

Critical
High
Normal
Low

When offering cloud services, the organisation needs to have planned processes or procedures for:

  • how the cloud service customer reports an information security event to the organisation
  • how the organisation reports information security events to cloud service customers
  • how the cloud service customer can track the status of a previously reported information security event
Connected other frameworks and requirements:
ID.RA-3: Threat identification
NIST CSF
DE.DP-4: Event detection
NIST CSF
RS.CO-3: Information sharing
NIST CSF
RC.CO-1: Public relations
NIST CSF
16: Information security incident management
ISO 27017
No items found.