MIL1 requirements
a. Cybersecurity incident response personnel are identified, and roles are assigned, at least in an ad hoc manner
b. Responses to cybersecurity incidents are executed, at least in an ad hoc manner, to limit impact to the function and restore normal operations
c. Reporting of incidents is performed (for example, internal reporting, ICS-CERT, relevant ISACs), at least in an ad hoc manner
MIL2 requirements
d. Cybersecurity incident response plans that address all phases of the incident lifecycle are established and maintained
e. Cybersecurity incident response is executed according to defined plans and procedures
f. Cybersecurity incident response plans include a communications plan for internal and external stakeholders
g. Cybersecurity incident response plan exercises are conducted periodically and according to defined triggers, such as system changes and external events
h. Cybersecurity incident lessons-learned activities are performed and corrective actions are taken, including updates to the incident response plan
MIL3 requirements
i. Cybersecurity incident root-cause analysis is performed and corrective actions are taken, including updates to the incident response plan
j. Cybersecurity incident responses are coordinated with vendors, law enforcement, and other external entities as appropriate, including support for evidence collection and preservation
k. Cybersecurity incident response personnel participate in joint cybersecurity exercises with other organizations
l. Cybersecurity incident responses leverage and trigger predefined states of operation (SITUATION-3g)
The organization shall ensure that clear persons are assigned to incident management responsibilities, e.g. handling the first response for incidents.
Incident management personnel need to be instructed and trained to understand the organization's priorities in dealing with security incidents.
The organization has defined a process and the team involved in responding promptly to security incidents and deciding on the appropriate actions.
The first level response process includes at least:
In the event of an incident, communication with internal and external stakeholders must be in accordance with the incident response plan.