RC.CO-03.359
Does your organization have a formal process for updating senior leadership on the recovery status and progress during major security incidents?
Explanation
Regular updates to senior leadership during major incidents ensure they have visibility into the recovery efforts, can make informed decisions, and provide necessary resources to support the incident response team. These updates typically include current status, estimated time to resolution, business impact assessment, and any escalation needs. Evidence could include documented communication protocols specific to major incidents, templates for executive briefings during incidents, meeting minutes from past incident reviews showing leadership updates, or a section in the incident response plan that outlines the cadence and format for leadership reporting during major incidents.
Implementation Example
Regularly update senior leadership on recovery status and restoration progress for major incidents
ID: RC.CO-03.359
Context
- Function
- RC: RECOVER
- Category
- RC.CO: Incident Recovery Communication
- Sub-Category
- Recovery activities and progress in restoring operational capabilities are communicated to designated internal and external stakeholders

