unified

UC-LOG-06 — Evaluate events and declare incidents against defined criteria

Define written criteria for declaring a security incident, including thresholds that identify a reportable personal-data breach. Evaluate analyzed events against those criteria, declare incidents and initiate the response process when criteria are met, and record the assessment and rationale for every evaluated event. For reportable personal-data breaches, notify the competent regulator within the mandated statutory window with the prescribed content, and document all breaches, their effects, and remediation regardless of whether notification was required.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
Logging, Monitoring & Detection
type
detective
category
administrative

Details

unified_id
UC-LOG-06
title
Evaluate events and declare incidents against defined criteria
statement
Define written criteria for declaring a security incident, including thresholds that identify a reportable personal-data breach. Evaluate analyzed events against those criteria, declare incidents and initiate the response process when criteria are met, and record the assessment and rationale for every evaluated event. For reportable personal-data breaches, notify the competent regulator within the mandated statutory window with the prescribed content, and document all breaches, their effects, and remediation regardless of whether notification was required.
domain
Logging, Monitoring & Detection
control_type
detective
control_category
administrative
members
  • framework
    nist-csf-2
    control_id
    DE.AE-08
    coverage
    full
    relationship
    superset_of
  • framework
    soc2
    control_id
    CC7.3
    coverage
    full
    relationship
    superset_of
  • framework
    gdpr
    control_id
    GDPR-Art33
    coverage
    full
    relationship
    superset_of
guidance

    Source

    No record-specific source URL is provided.

    Connections