Cybersecurity incident declaration criteria are updated periodically and according to defined triggers, such as organizational changes, lessons learned from plan execution, or newly identified threats
To maximize the investment in the incident detection and response process, incident declaration criteria should be maintained to reflect an organization's evolving risk tolerance and threat environment. Also, updating the criteria based on lessons learned in this process can help the organization to be more efficient and effective in dealing with future events.
Related Practices · Progression: This practice is part of a practice progression. Practice progressions are groups of related practices that represent increasingly complete or more advanced implementations of an activity. The practices in this progression include: RESPONSE-2a, RESPONSE-2c, RESPONSE-2e, RESPONSE-2h.