Does your organization have a formal process for updating senior leadership on the recovery status and progress during major security incidents?
Explanation
Regular updates to senior leadership during major incidents ensure they have visibility into the recovery efforts, can make informed decisions, and provide necessary resources to support the incident response team. These updates typically include current status, estimated time to resolution, business impact assessment, and any escalation needs.
Evidence could include documented communication protocols specific to major incidents, templates for executive briefings during incidents, meeting minutes from past incident reviews showing leadership updates, or a section in the incident response plan that outlines the cadence and format for leadership reporting during major incidents.
Implementation Example
Regularly update senior leadership on recovery status and restoration progress for major incidents
ID: RC.CO-03.359
Context
- Function
- RC: RECOVER
- Category
- RC.CO: Incident Recovery Communication
- Sub-Category
- Recovery activities and progress in restoring operational capabilities are communicated to designated internal and external stakeholders
Related questions
- Does your organization have a formal process for managing public relations during and after a security incident?
- Does your organization have a documented process for repairing reputation damage following a security incident?
- Does your organization have documented procedures for securely sharing recovery information and restoration progress with stakeholders during incident response?
- Does your organization adhere to contractually defined rules and protocols for incident information sharing with suppliers?
- Has your organization established a formal process for coordinating crisis communication with critical suppliers during security incidents?
- Does your organization have documented breach notification procedures that are followed during data breach recovery incidents?

