T8.2.7 - INFORMATION SECURITY INCIDENT DOCUMENTATION Implementation Guidance
The entity shall document all information security incidents.
Back to T2.8.7 - P4 - INFORMATION SECURITY INCIDENT DOCUMENTATION
Documenting information security incidents includes, for example, maintaining records about each incident, the status of the incident, and other pertinent information necessary for forensics, evaluating incident details, trends, and handling. Incident information can be obtained from a variety of sources including, for example, incident reports, incident response teams, audit monitoring, network monitoring, physical access monitoring, and user/administrator reports.
Back to T2.8.7 - P4 - INFORMATION SECURITY INCIDENT DOCUMENTATION