id: "SA-15(10)" title: "Incident Response Plan" family: "SA" family_name: "System and Services Acquisition" sort_id: "sa-15.10" priority: "P1" implementation_level: "organization" parent: "SA-15" enhancement: True


Statement

Require the developer of the system, system component, or system service to provide, implement, and test an incident response plan.

Guidance

The incident response plan provided by developers may provide information not readily available to organizations and be incorporated into organizational incident response plans. Developer information may also be extremely helpful, such as when organizations respond to vulnerabilities in commercial off-the-shelf products.

Assessment Objective: the developer of the system, system component, or system service is required to provide an incident response plan;

Assessment Objective: the developer of the system, system component, or system service is required to implement an incident response plan;

Assessment Objective: the developer of the system, system component, or system service is required to test an incident response plan.

System and services acquisition policy

procedures addressing incident response, standards, and tools

solicitation documentation

acquisition documentation

service level agreements

acquisition contracts for the system, system components or services

acquisition documentation

solicitation documentation

service level agreements

developer incident response plan

system security plan

privacy plan

supply chain risk management plan

other relevant documents or records

Organizational personnel with system and service acquisition responsibilities

organizational personnel with information security responsibilities

system developer

organizational personnel with supply chain risk management responsibilities