Cybersecurity incident declaration criteria are updated periodically and according to defined triggers, such as organisational changes, lessons learned from plan execution, or newly identified threats
Context and Guidance: To maximise the investment in the incident detection and response process, incident declaration criteria should be maintained to reflect an organisation's evolving risk tolerance and threat environment. Also, updating the criteria based on lessons learned in this process can help the organisation to be more efficient and effective in dealing with future events.
Related Practices • Progression: This practice is part of a practice progression. Practice progressions are groups of related practices that represent increasingly complete or more advanced implementations of an activity. The practices in this progression include: RESPONSE-2a, RESPONSE-2c, RESPONSE-2e, RESPONSE-2h.