What does ETSI EN 319 401 require for security incidents?
Clause 7.9 of ETSI EN 319 401 V3.2.1 covers monitoring and logging, incident response, reporting, event assessment and classification, and post-incident review. It requires a documented incident handling policy with roles and procedures for timely detection, analysis, containment, response, recovery, documentation, and reporting.
The standard defines incident handling as actions and procedures to prevent, detect, analyse, contain, respond to, and recover from an incident. It also defines an information security incident as related and identified information security events that can harm assets or compromise operations, so the incident process should connect event intake, severity assessment, response, and lessons learned.
- Detect potential security incidents through continuous monitoring and logging mechanisms for the TSP's network and information systems.
- Define the assets subject to logging from the risk assessment; protect and back up logs for a predefined period; maintain synchronized time sources where feasible; and monitor the logging system independently.
- Use incident response procedures that include containment, eradication, and recovery, then keep comprehensive documentation throughout detection and response.
- Analyse reported events, assess severity, and be able to reassess and reclassify events when new inputs appear.
Primary ETSI source for clause 7.9 requirements on monitoring, logging, incident response, reporting, event assessment, classification, and post-incident review.