RS.CO-02.331
Does your organization have documented procedures for notifying business partners and customers of security incidents in accordance with contractual obligations?
Explanation
This question assesses whether your organization has established formal processes to communicate security incidents to external stakeholders as required by contracts and agreements. Having clear notification procedures helps maintain trust, enables affected parties to take appropriate actions, and demonstrates compliance with legal and contractual obligations. Evidence could include an incident response plan with specific sections on external communications, notification templates, a communication matrix showing which stakeholders should be notified for different incident types, and records of previous notifications that demonstrate adherence to contractual timeframes.
Implementation Example
Notify business partners and customers of incidents in accordance with contractual requirements
ID: RS.CO-02.331
Context
- Function
- RS: RESPOND
- Category
- RS.CO: Incident Response Reporting and Communication
- Sub-Category
- Internal and external stakeholders are notified of incidents

