CMMC Practice Requirement:

Analyze and triage events to support event resolution and incident declaration.

CMMC Requirement Explanation:

By categorizing incidents you can efficiently respond to them and escalate them to the appropriate persons.

Example CMMC Implementation:

Establish incident categories, an example is the U.S. CERT's Federal Agency Incident Categories. When a security incident occurs categorize it so that you can respond to it appropriately. Use the assigned category to help prioritize incident response. Analyze incidents to determine if they are isolated or part of larger problem.

Scenario(s):

- Scenario 1:

Your company uses the U.S. CERT's Federal Agency Incident Categories to categorize security incidents. You discover malware installed on one of your systems and label it as a Category 3 incident. Because it is a category 3 incident it warrants an immediate response and must be reported to management within 1 hour. Your staff responds to the incident and analyzes it determining that the malware has only infect one machine. Your staff responds to and closes the incident and responds to it in accordance with your incident response plan.
 

Discover Our NIST SP 800-171 Solutions:

 /assets/images/compliance_accelerator_white.png

Compliance Accelerator

For contractors seeking compliance
 /assets/images/quantum_assessor_white.png

Quantum Assessor

For IT service providers
 /assets/images/supply_chain_logo_white.png

Supply Chain Verifier

For contractors seeking to verify partner compliance