The organization shall collaborate and share information about its critical system's related security incidents and mitigation measures with designated partners.
Guidance
No additional guidance on this topic.
Communication of effectiveness of protection technologies shall be shared with appropriate parties.
Guidance
No additional guidance on this topic.
The organization shall implement, where feasible, automated mechanisms to assist in information collaboration.
The organization has defined procedures to ensure that the original reporter and other personnel involved in the incident are informed of the outcome of the incident management.
Linked personnel can be documented on an optional field on the incident documentation template.
The knowledge gained from analyzing and resolving security incidents should be used to reduce the likelihood of future incidents and their impact.
The organization regularly analyzes incidents as a whole. This process examines the type, amount and cost of incidents with the aim of identifying recurrent and significant incidents that need more action.
If recurrent incidents requiring response are identified, based on them:
Organization should share threat intelligence information actively with other organizations to improve its own threat awareness.