1 Scope
This document provides guidelines for multiple organizations handling information
security incidents in a coordinated manner. It also addresses the impacts of external
cooperation on the internal incident management of an individual organization and
provides guidelines for an individual organization to adapt to the coordination process.
Furthermore, it provides guidelines for the coordination team, if it exists, to perform
coordination activities supporting the cross-organization incident response.
The principles given in this document are generic and are intended to be applicable
to multiple organizations to work together to handle information security incidents,
regardless of their types, sizes or nature. Organizations can adjust the guidance
given in this document according to their type, sizes and nature of business in relation
to the information security risk situation. This document is also applicable to an
individual organization that participates in partner relationships.