IR-7(2): Coordination with External Providers

Control Family:

Incident Response

CSF v1.1 References:

Baselines:

(Not part of any baseline)

Previous Version:

Control Statement

  1. Establish a direct, cooperative relationship between its incident response capability and external providers of system protection capability; and
  2. Identify organizational incident response team members to the external providers.

Supplemental Guidance

External providers of a system protection capability include the Computer Network Defense program within the U.S. Department of Defense. External providers help to protect, monitor, analyze, detect, and respond to unauthorized activity within organizational information systems and networks. It may be beneficial to have agreements in place with external providers to clarify the roles and responsibilities of each party before an incident occurs.