// Level 3 · Controls

Security Incident Mgmt, E-Discovery, & Cloud Forensics

SEF domain controls.

SEF-01High

Security Incident Management Policy and Procedures

Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for Security Incident Management, E-Discovery, and Cloud Forensics.

SEF-02Medium

Service Management Policy and Procedures

Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for the timely management of security incidents.

SEF-03High

Incident Response Plans

Establish, document, approve, communicate, apply, evaluate and maintain a security incident response plan, which includes but is not limited to: relevant internal departments, impacted CSCs, and other business critical relationships (such as supply-chain) that may be impacted.

SEF-04High

Incident Response Testing

Test and update as necessary incident response plans at planned intervals or upon significant organizational or environmental changes for effectiveness.

SEF-05High

Incident Response Metrics

Establish and monitor information security incident metrics.

SEF-06Medium

Event Triage Processes

Define, implement and evaluate processes, procedures and technical measures supporting business processes to triage security-related events.

SEF-07High

Security Breach Notification

Define and implement, processes, procedures and technical measures for security breach notifications.

SEF-08Medium

Points of Contact Maintenance

Maintain points of contact for applicable regulation authorities, national and local law enforcement, and other legal jurisdictional authorities.