ABSTRACT

The “Information Security Incident Management” clause is new in the second edition, but it is mostly composed of existing controls. The five controls and two control objectives focus on notification, containment, and management of information security incidents. Management should closely review this clause to ensure that their environment and operations fully address the controls in this clause.