Organization should establish an incident response program
Critical
Azure
General
manual-cis-incident-management
How to fix it
Establish and maintain an incident response program with designated team, procedures, communication plans, and post-incident reviews. Test the plan at least annually through tabletop exercises.
How to verify
- Verify incident response plan exists
- Confirm incident response team is designated
- Verify annual test/exercise results
- Confirm post-incident review records
Compliance frameworks
Is your environment compliant with this rule?
CGPulse checks it — and 621 others — against your Azure and AWS accounts with read-only access.
Related Azure rules
- Action Group should be enabled
- Activity Log Alert should be enabled
- AKS cluster logs should be sent to Log Analytics
- AKS cluster must enable RBAC
- AKS cluster must enable RBAC
- AKS cluster should be a private cluster
- AKS cluster should disable local accounts
- AKS cluster should enable Azure RBAC for Kubernetes