RS.MA-02.312
Does your organization have a process to initially screen and validate incident reports to determine if they are cybersecurity-related and require incident response procedures?
Explanation
This question assesses whether your organization has a triage mechanism to properly classify incoming security alerts or reports before allocating incident response resources. Without proper screening, teams may waste resources on false positives or non-security events, while potentially missing critical incidents that require immediate attention. Effective screening helps prioritize response efforts and ensures appropriate escalation paths are followed. Evidence could include a documented incident triage procedure, a decision tree for incident classification, screenshots of a ticketing system showing initial assessment fields, or examples of incident intake forms with preliminary assessment criteria.
Implementation Example
Preliminarily review incident reports to confirm that they are cybersecurity-related and necessitate incident response activities
ID: RS.MA-02.312
Context
- Function
- RS: RESPOND
- Category
- RS.MA: Incident Management
- Sub-Category
- Incident reports are triaged and validated

