RS.MA-01.310
Does your organization assign a designated incident lead for each security incident?
Explanation
Designating a specific incident lead for each security incident ensures clear accountability, streamlined communication, and effective coordination of response activities. This role is responsible for making critical decisions, managing the incident response team, and serving as the central point of contact throughout the incident lifecycle. Evidence of this practice could include an incident response plan or playbook that clearly defines the incident lead role and selection process, documentation of past incidents showing assigned leads, or a roster of qualified staff who can serve as incident leads with their areas of expertise.
Implementation Example
Designate an incident lead for each incident
ID: RS.MA-01.310
Context
- Function
- RS: RESPOND
- Category
- RS.MA: Incident Management
- Sub-Category
- The incident response plan is executed in coordination with relevant third parties once an incident is declared

