ctl-037
Cross-functional incident response is exercised twice yearly.
- Type
- DETECTIVE
- Automation
- MANUAL
- Frequency
- QUARTERLY
- Owner
- Information Security
Control Design Assessment (CDA)
Procedures evaluating whether the control is designed adequately.
No design-assessment procedures defined yet.
Control Operating Effectiveness (COE)
Procedures evaluating whether the control operated over the testing period.
No operating-effectiveness procedures defined yet.
Linked risks
- Ransomware disruptionmitigation 2
- MSSP detection blind spotsmitigation 1
Framework mappings & latest test
SEF-04
Latest test:PASS2026-04-25