Information/cybersecurity incidents shall be categorized according to the level of severity and impact consistent with the evaluation criteria included the incident response plan.
Guidance
- It should be considered to determine the causes of an information/cybersecurity incident and implement a corrective action in order that the incident does not recur or occur elsewhere.
- The effectiveness of any corrective action taken should be reviewed.
- Corrective actions should be appropriate to the effects of the information/cybersecurity incident encountered.
All security incidents are addressed in a consistent manner to improve security based on what has happened.
In the incident treatment process:
The organization has defined a process and the team involved in responding promptly to security incidents and deciding on the appropriate actions.
The first level response process includes at least: