id: "SA-15(10)" title: "Incident Response Plan" family: "SA" family_name: "System and Services Acquisition" sort_id: "sa-15.10" priority: "P1" implementation_level: "organization" parent: "SA-15" enhancement: True
Statement
Require the developer of the system, system component, or system service to provide, implement, and test an incident response plan.
Guidance
The incident response plan provided by developers may provide information not readily available to organizations and be incorporated into organizational incident response plans. Developer information may also be extremely helpful, such as when organizations respond to vulnerabilities in commercial off-the-shelf products.
Assessment Objective: the developer of the system, system component, or system service is required to provide an incident response plan;
Assessment Objective: the developer of the system, system component, or system service is required to implement an incident response plan;
Assessment Objective: the developer of the system, system component, or system service is required to test an incident response plan.
System and services acquisition policy
procedures addressing incident response, standards, and tools
solicitation documentation
acquisition documentation
service level agreements
acquisition contracts for the system, system components or services
acquisition documentation
solicitation documentation
service level agreements
developer incident response plan
system security plan
privacy plan
supply chain risk management plan
other relevant documents or records
Organizational personnel with system and service acquisition responsibilities
organizational personnel with information security responsibilities
system developer
organizational personnel with supply chain risk management responsibilities