Docy Child

BIZOPS-8 Security Incident Testing

Estimated reading: 2 minutes 597 views

What is this control about?

For small companies, it is often the case that they declare not having any incidents or very few.

The most common reason for the lack of incidents is that these incidents are never identified. You could have many security policy violations occurring each day, but if you don’t have a way of identifying them, you will never know. Therefore, the incident management policy should identify and list all possible violations and ways to detect them.

It is recommended that you test the whole incident reporting, analysis and remediation process at  least once a year in order to identify any inefficiencies and improve the process. This annual test can be waived if there had been instances of incidents.

Available tools in the marketplace

 No tools recommendation for this section’

Available templates

TrustCloud has a curated list of templates internally or externally sourced to help you get started. Click on the link for a downloadable version:

Control implementation

This is only applicable if there had been no incident during the year:

Define and document a test plan to gage the effectiveness of the incident management plan.

Designate a team or personnel responsible for testing the incident response plan

Choose a day to perform the test and document the process in a ticketing system

If they have been an incident, simply ensure there is a process to document and remediate incidents.

What evidence do auditors look for?

Most auditors, at a minimum are looking for the below suggested action:

  • (in case there has been an incident) Provide the incident response testing ticket documenting the identification, analysis, resolution

Evidence example

From the suggested action above, an example is provided below.

  1. Provide the incident response testing ticket documenting the identification, analysis, and resolution.

TrustCloud example showing the ticket created to document the incident.

BIZOPS 8 screenshot1

Join the conversation

Twitter Facebook LinkedIn

❤️  Joyfully crafted by a 100% distributed team.