CIS Controls v8

CIS 17 Incident Response Management

Starts in IG2 | Prepare and execute repeatable incident response operations.

Implementation Actions

  • Maintain scenario playbooks.
  • Exercise response workflows.
  • Track after-action improvements.

Evidence Examples

  • Incident response plan
  • Exercise records
  • Corrective action tracker

Suggested Metrics

  • Containment time trend
  • Corrective action closure rate