What should software incident response requirements cover?

Discussion

Verified answerLast verified: 2026-08-02
  • Author
    Posts
  • #3333

    A promise to follow standard incident procedures does not tell the buyer when it will be notified or what help it will receive. Which responsibilities should be made explicit?

    #3334
    Accepted editorial answer

    Define what must be reported, the notification timeline, available contacts, required updates, evidence preservation, containment and recovery responsibilities, and the information provided for legal, privacy, security, and operational decisions.

    Cover exercises and post-incident work, as well as the first alert. Ask how the supplier detects incidents, coordinates subcontractors, restores service, communicates changes in scope, supports investigations, and tracks corrective actions after recovery.

    CISA’s vendor questions covers detection, breach communication, support, backups, and resilience. NIST SP 800-61 Rev. 3 integrates preparation, detection, response, recovery, communication, and improvement into risk management.

  • You must be logged in to reply to this topic.

Reply to this discussion

You must be logged in to reply. Editors verify buy-side questions and cite reviews when answering.

Create an account