What type of information should be shared with external stakeholders during a cybersecurity incident?
- A.No information should ever be shared externally, because forensics is excluded from Respond
- B.Only financial impact estimates
- C.All technical details of the breach including system passwords, reasoning that NIST staffs incident bridges
- D.Information consistent with response plans, legal requirements, and organizational policies
Why D is correct
Information shared externally should be consistent with response plans, legal and regulatory requirements, and organizational policies to ensure appropriate disclosure without compromising the investigation.
Know someone studying for NIST CSF? Send them this one.