The organization shall coordinate information/cybersecurity incident response actions with all predefined stakeholders.
Guidance
- Stakeholders for incident response include for example, mission/business owners, organization's critical system owners, integrators, vendors, human resources offices, physical and personnel security offices, legal departments, operations personnel, and procurement offices.
- Coordination with stakeholders occurs consistent with incident response plans.
In the event of an incident, communication with internal and external stakeholders must be in accordance with the incident response plan.
In the event of an incident, the implementation of the response plan with stakeholders must be carried out as specified in the plan.