Correlate incident information and individual incident responses to achieve an organization-wide perspective on incident awareness and response.
Correlate incident information and individual incident responses to achieve an organization-wide perspective on incident awareness and response.
Implement a configurable capability to automatically disable the system if [Assignment: organization-defined security violations] are detected.
Implement an incident handling capability for incidents involving insider threats.
Coordinate an incident handling capability for insider threats that includes the following organizational entities [Assignment: organization-defined entities].
Coordinate with [Assignment: organization-defined external organizations] to correlate and share [Assignment: organization-defined incident information] to achieve a cross-organization perspective on incident awareness and more effective incident responses.
Employ [Assignment: organization-defined dynamic response capabilities] to respond to incidents.
Coordinate incident handling activities involving supply chain events with other organizations involved in the supply chain.
Establish and maintain an integrated incident response team that can be deployed to any location identified by the organization in [Assignment: organization-defined time period].
Analyze malicious code and/or other residual artifacts remaining in the system after the incident.
Analyze anomalous or suspected adversarial behavior in or related to [Assignment: organization-defined environments or resources].