Discussion
- AuthorPosts
- 7th August 2026 at 2:26 pm #3333
A promise to follow standard incident procedures does not tell the buyer when it will be notified or what help it will receive. Which responsibilities should be made explicit?
7th August 2026 at 2:26 pm #3334Accepted editorial answerDefine what must be reported, the notification timeline, available contacts, required updates, evidence preservation, containment and recovery responsibilities, and the information provided for legal, privacy, security, and operational decisions.
Cover exercises and post-incident work, as well as the first alert. Ask how the supplier detects incidents, coordinates subcontractors, restores service, communicates changes in scope, supports investigations, and tracks corrective actions after recovery.
CISA’s vendor questions covers detection, breach communication, support, backups, and resilience. NIST SP 800-61 Rev. 3 integrates preparation, detection, response, recovery, communication, and improvement into risk management.
- AuthorPosts
- You must be logged in to reply to this topic.