Hi all,
As discussed on the slack channel, I move this here:
The current incident management practice focuses on mostly on internal response activities (classification, RCA, forensics, team readiness). External communication is not well covered. There is a mention in O-IM-2-B but no criteria.
https://github.com/owaspsamm/core/blob/develop/model/activities/O-IM-2-B.yml:
rules for involvement of different stakeholders including senior management, Public Relations, Legal, privacy, Human Resources, external (law enforcement) authorities, and customers; specify mandatory timeframe to do so, if needed
This is becoming a compliance requirement in several jurisdictions (e.g. CRA Article 14, NIS2), but it also reflects a basic maturity expectation independent of regulation. A proper process is essential to give the clients an indication on how to handle an incident (in particular if the communication channel could be affected by the incident as well).
A possible addition for the quality crieteria could be:
L1: You have a defined owner responsible for external notifications
L2: You follow a documented process for customer notification and regulatory reporting
L3: You track notification success and customer reaction to improve your response process
Thoughts?
regards
Stefan
Hi all,
As discussed on the slack channel, I move this here:
The current incident management practice focuses on mostly on internal response activities (classification, RCA, forensics, team readiness). External communication is not well covered. There is a mention in O-IM-2-B but no criteria.
https://github.com/owaspsamm/core/blob/develop/model/activities/O-IM-2-B.yml:
This is becoming a compliance requirement in several jurisdictions (e.g. CRA Article 14, NIS2), but it also reflects a basic maturity expectation independent of regulation. A proper process is essential to give the clients an indication on how to handle an incident (in particular if the communication channel could be affected by the incident as well).
A possible addition for the quality crieteria could be:
L1: You have a defined owner responsible for external notifications
L2: You follow a documented process for customer notification and regulatory reporting
L3: You track notification success and customer reaction to improve your response process
Thoughts?
regards
Stefan