Skip to content

Incident External Communication #192

Description

@imix

Hi all,

As discussed on the slack channel, I move this here:

The current incident management practice focuses on mostly on internal response activities (classification, RCA, forensics, team readiness). External communication is not well covered. There is a mention in O-IM-2-B but no criteria.

https://github.com/owaspsamm/core/blob/develop/model/activities/O-IM-2-B.yml:

rules for involvement of different stakeholders including senior management, Public Relations, Legal, privacy, Human Resources, external (law enforcement) authorities, and customers; specify mandatory timeframe to do so, if needed

This is becoming a compliance requirement in several jurisdictions (e.g. CRA Article 14, NIS2), but it also reflects a basic maturity expectation independent of regulation. A proper process is essential to give the clients an indication on how to handle an incident (in particular if the communication channel could be affected by the incident as well).

A possible addition for the quality crieteria could be:
L1: You have a defined owner responsible for external notifications
L2: You follow a documented process for customer notification and regulatory reporting
L3: You track notification success and customer reaction to improve your response process

Thoughts?

regards
Stefan

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

  • Status
    Todo

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions