Internal and external stakeholders (for example, executives, attorneys, government agencies, connected organizations, vendors, sector organizations, regulators) are identified and notified of incidents based on situational awareness reporting requirements (SITUATION-3d)
Incidents that have been declared and that require a response must be communicated to stakeholders whose involvement is necessary in implementing, managing, and bringing to closure an appropriate and timely solution. Event and incident notification should be guided by the reporting requirements defined in SITUATION-3d. Miscommunications or inaccurate information about organizational incidents can have dire effects that far exceed the potential damage caused by an incident itself. Therefore, the function must proactively manage communications when incidents are detected and throughout their life cycle.
Related Practices · Dependency: Implementing this practice depends upon prior implementation of SITUATION-3d. · Information Sharing: This practice is part of a group of cross-domain practices that enable information sharing with organizational stakeholders. These include: THREAT-1i, THREAT-2h, THREAT-2k, RISK-1c1d, SITUATION-3a, SITUATION-3c, SITUATION-3d, SITUATION-3e, RESPONSE-2g, RESPONSE-3c, RESPONSE-3f.