Skip to Content

 Incident Response (IR)

Automated Incident Handling Processes IR-4(1)

Overview:The organization employs automated mechanisms to support the incident handling process. Supplemental Guidance:Automated mechanisms supporting incident handling processes include, for example, online incident management systems. Action Items... Read More

Automated Reporting IR-6(1)

Overview:The organization employs automated mechanisms to assist in the reporting of security incidents. Supplemental Guidance: Related control:IR-7. Action Items:1) Implement automated mechanisms to support incident reporting procedures Related... Read More

Coordination with External Providers IR-7(2)

Overview:The organization:(a) Establishes a direct, cooperative relationship between its incident response capability and external providers of information system protection capability; and(b) Identifies organizational incident response team members... Read More

Coordination with Related Plans IR-3(2)

Overview:The organization coordinates incident response testing with organizational elements responsible for related plans. Supplemental Guidance:Organizational plans related to incident response testing include, for example, Business Continuity... Read More

Exposure to Unauthorized Personnel IR-9(4)

Overview:The organization employs [Assignment: organization-defined security safeguards] for personnel exposed to information not within assigned access authorizations. Supplemental Guidance:Security safeguards include, for example, making personnel... Read More

Incident Handling IR-4

Overview: The organization:a. Implements an incident handling capability for security incidents that includes preparation, detection and analysis, containment, eradication, and recovery;b. Coordinates incident handling activities with contingency... Read More

Incident Monitoring IR-5

Overview:The organization tracks and documents information system security incidents. Supplemental Guidance:Documenting information system security incidents includes, for example, maintaining records about each incident, the status of the incident,... Read More

Incident Reporting IR-6

Overview:The organization:a. Requires personnel to report suspected security incidents to the organizational incident response capability within [Assignment: organization-defined time period]; andb. Reports security incident information to ... Read More

Incident Response Assistance IR-7

Overview:The organization provides an incident response support resource, integral to the organizational incident response capability that offers advice and assistance to users of the information system for the handling and reporting of security... Read More

Results 1 - 10 of 17