IR-07 Incident Response Assistance

Control: The organization provides an incident response support resource that offers advice and assistance to users of the information system for the handling and reporting of security incidents. The support resource is an integral part of the organization’s incident response capability.

Supplemental Guidance: Possible implementations of incident response support resources in an organization include a help desk or an assistance group and access to forensics services, when required.

Control Enhancements: (1) The organization employs automated mechanisms to increase the availability of incident response- related information and support.

Baseline: LOW IR-7 MOD IR-7 (1) HIGH IR-7 (1)

Family: Incident Response

Class: Operational

ISO 17799 mapping: 14.1.3

COBIT 4.1 mapping: DS8.1

PCI-DSS v2 mapping: 12.9.3