Designate one key person, and at least one backup, who will manage the enterprise’s incident
handling process. Management personnel are responsible for the coordination and documentation
of incident response and recovery efforts and can consist of employees internal to the enterprise,
service providers, or a hybrid approach. If using a service provider, designate at least one person
internal to the enterprise to oversee any third-party work. Review annually, or when significant
enterprise changes occur that could impact this Safeguard.
The organization shall ensure that clear persons are assigned to incident management responsibilities, e.g. handling the first response for incidents.
Incident management personnel need to be instructed and trained to understand the organization's priorities in dealing with security incidents.
The organization should appoint a primary and backup incident handler, define their roles and responsibilities, establish protocols for working with service providers, offer regular training, and implement a communication plan to ensure effective incident response management.