πΌ RS.MA-02: Incident reports are triaged and validated
- Contextual name: πΌ RS.MA-02: Incident reports are triaged and validated
- ID:
/frameworks/nist-csf-v2.0/rs-ma/02
- Located in: πΌ Incident Management (RS.MA)
Descriptionβ
- Preliminarily review incident reports to confirm that they are cybersecurity-related and necessitate incident response activities
- Apply criteria to estimate the severity of an incident
Similarβ
- Sections
/frameworks/nist-csf-v1.1/rs-an/01
/frameworks/nist-csf-v1.1/rs-an/02
/frameworks/nist-sp-800-53-r5/ir/04
/frameworks/nist-sp-800-53-r5/ir/05
/frameworks/nist-sp-800-53-r5/ir/06
Similar Sections (Take Policies From)β
Section | Sub Sections | Internal Rules | Policies | Flags |
---|---|---|---|---|
πΌ NIST CSF v1.1 β πΌ RS.AN-1: Notifications from detection systems are investigated | 19 | 22 | ||
πΌ NIST CSF v1.1 β πΌ RS.AN-2: The impact of the incident is understood | ||||
πΌ NIST SP 800-53 Revision 5 β πΌ IR-4 Incident Handling | 15 | |||
πΌ NIST SP 800-53 Revision 5 β πΌ IR-5 Incident Monitoring | 1 | |||
πΌ NIST SP 800-53 Revision 5 β πΌ IR-6 Incident Reporting | 3 |
Sub Sectionsβ
Section | Sub Sections | Internal Rules | Policies | Flags |
---|
Policies (22)β
Policy | Logic Count | Flags |
---|---|---|
π AWS Account Multi-Region CloudTrail is not enabled π’ | 1 | π’ x6 |
π AWS CloudTrail Log File Validation is not enabled π’ | 1 | π’ x6 |
π AWS CloudTrail S3 Bucket Access Logging is not enabled. π’ | 1 | π’ x6 |
π AWS KMS Symmetric CMK Rotation is not enabled π’ | 1 | π’ x6 |
π AWS S3 Bucket Server Access Logging is not enabled π’ | 1 | π’ x6 |
π AWS VPC Flow Logs are not enabled π’ | 1 | π x1, π’ x5 |
π Azure Diagnostic Setting for Azure Key Vault is not enabled π’ | π’ x3 | |
π Azure PostgreSQL Flexible Server connection_throttle.enable Parameter is not set to ON π’ | 1 | π’ x6 |
π Azure PostgreSQL Flexible Server log_checkpoints Parameter is not set to ON π’ | 1 | π’ x6 |
π Azure PostgreSQL Flexible Server log_retention_days Parameter is less than 4 days π’ | 1 | π’ x6 |
π Azure PostgreSQL Single Server log_connections Parameter is not set to ON π’ | 1 |