risk
No or insufficient incident-response procedures
Without documented, tested incident-response procedures, breaches and failures are handled inconsistently, slowly, or ineffectively, prolonging exposure and amplifying loss.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- category
- cyber_security
- domain
- Incident Management & Response
- taxonomy
- iso-27005-vulnerability
- nist-privacy-risk
- inherent_rating
- high
Details
- risk_id
- ir-no-response-procedures
- category
- cyber_security
- likelihood
- medium
- impact
- high
- inherent_rating
- high
- treatment
- mitigate
- taxonomies
- iso-27005-vulnerability
- nist-privacy-risk
Source
No record-specific source URL is provided.
Connections
- UC-IR-01 — Maintain an approved incident response plan mitigates No or insufficient incident-response procedures
- strength
- primary
- rationale
- The approved, distributed, periodically-reviewed IR plan is the documented response procedure whose absence defines the risk.
- UC-IR-02 — Train responders and test the incident response capability mitigates No or insufficient incident-response procedures
- strength
- primary
- rationale
- Role-based training plus tabletop testing validates the procedures work and are executed, directly countering inconsistent, slow, or ineffective handling.
- UC-IR-03 — Provide channels to report events and obtain response help mitigates No or insufficient incident-response procedures
- strength
- primary
- rationale
- Operating monitored reporting channels and support routes events promptly into triage, directly reducing slow/inconsistent incident handling at intake.
- UC-IR-10 — Learn from incidents and communicate corrective actions mitigates No or insufficient incident-response procedures
- strength
- related
- rationale
- Converting post-incident lessons into corrective actions improves procedures over time — a second-order feedback loop presupposing the base procedures, not the operative defense against their absence.
- UC-ASSET-11 — Improve security plans and processes from operational lessons mitigates No or insufficient incident-response procedures
- strength
- related
- rationale
- Improving IR/cyber plans after exercises and incidents is a second-order feedback loop presupposing the base procedures UC-IR-01/02 establish and test; it contributes but is not the operative defense against their absence.
- UC-IR-04 — Triage, categorize, and escalate reported security events mitigates No or insufficient incident-response procedures
- strength
- primary
- rationale
- Triage, classification, prioritization, and threshold-based escalation directly make incident handling consistent, prioritized, and timely.