12: Information Security Incident Management
This category focuses on ensuring a consistent and effective approach to managing information security incidents, including communication on security events and weaknesses. It involves planning, monitoring, and responding to incidents to minimize adverse impacts and ensure that lessons are learned to prevent future incidents.
Controls (A.16):
Control A.16.1.1: Responsibilities and Procedures
Control A.16.1.2: Reporting Information Security Events
Control A.16.1.3: Reporting Information Security Weaknesses
Control A.16.1.4: Assessment of and Decision on Information Security Events
Control A.16.1.5: Response to Information Security Incidents
Control A.16.1.6: Learning from Information Security Incidents
Control A.16.1.7: Collection of Evidence
Previous11. Supplier RelationshipsNext13. Information Security Aspects of Business Continuity Management
Last updated