CJIS - CSA ISO Establishes Security Incident Response Procedures, v1.0

Defines conformance and assessment criteria for verifying that an organization's CSA ISO established security incident response and reporting procedures.
If an assessment step references organization-defined elements (E.g. <organization-defined personnel or roles>, <organization-defined frequency>, etc.), corresponding citations/excerpts must be provided to confirm that the organization has established and documented these values and that they apply as referenced in the conformance criteria.

Similarly, if a "Selection" among multiple options (e.g. [Selection (one or more): as needed; ]) is specified, evidence must be provided to establish that the option(s) implemented by the organization have been defined and documented.

The assessment step shall not be marked as satisfied without this evidence.

Assessment Step

1
CSA ISO Establishes Incident Response Procedures (CSAISOEstablishesIncidentResponseProcedures)
Has the organization's CSA ISO established security incident response and reporting procedures that enable the discovery, investigation, and documentation of security incidents and reporting of major security incidents to the CSA, the affected criminal justice agency, and the FBI CJIS Division ISO?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
If conformance criteria reference organization-defined elements (e.g. <organization-defined personnel or roles>, <organization-defined frequency>, etc.), these values must be defined and documented by the organization.

Similarly, if the criteria specify a "Selection" among multiple options (e.g. [Selection (one or more): as needed; ]), the option(s) implemented by the organization must also be defined and documented.

Conformance Criteria (1)

C1
The CSA ISO shall:
4. Establish a security incident response and reporting procedure to discover, investigate, document, and report to the CSA, the affected criminal justice agency, and the FBI CJIS Division ISO major incidents that significantly endanger the security or integrity of CJI.
Citation
CJIS-SP-V5-4
Section 3.2.8.