RC.CO-01
Does your organization have a formal process for managing public relations during and after a security incident?
Explanation
This question assesses whether your organization has established protocols for communicating with the public, media, customers, and other stakeholders during and after a security incident. Effective public relations management during incident recovery helps maintain trust, control the narrative, and minimize reputational damage while ensuring accurate and appropriate information is released. Evidence could include a documented crisis communication plan, designated PR spokesperson roles, pre-approved statement templates, media training records for key personnel, or a communications workflow that shows approval chains for public statements during incidents.
Context
- Function
- RC: RECOVER
- Category
- RC.CO: Incident Recovery Communication
- Sub-Category
- Public relations are managed

