Skip to main content

πŸ’Ό ID.IM-04: Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved

  • Contextual name: πŸ’Ό ID.IM-04: Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved
  • ID: /frameworks/nist-csf-v2.0/id-im/04
  • Located in: πŸ’Ό Improvement (ID.IM)

Description​

  1. Establish contingency plans (e.g., incident response, business continuity, disaster recovery) for responding to and recovering from adverse events that can interfere with operations, expose confidential information, or otherwise endanger the organization's mission and viability
  2. Include contact and communication information, processes for handling common scenarios, and criteria for prioritization, escalation, and elevation in all contingency plans
  3. Create a vulnerability management plan to identify and assess all types of vulnerabilities and to prioritize, test, and implement risk responses
  4. Communicate cybersecurity plans (including updates) to those responsible for carrying them out and to affected parties
  5. Review and update all cybersecurity plans annually or when a need for significant improvements is identified

Similar​

  • Sections
    • /frameworks/nist-csf-v1.1/pr-ip/09
    • /frameworks/nist-csf-v1.1/pr-ip/10
    • /frameworks/nist-csf-v1.1/rs-im/01
    • /frameworks/nist-csf-v1.1/rc-im/01
    • /frameworks/nist-sp-800-53-r5/cp/02
    • /frameworks/nist-sp-800-53-r5/ir/08
    • /frameworks/nist-sp-800-53-r5/pl/02
    • /frameworks/nist-sp-800-53-r5/sr/02

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό PR.IP-9: Response plans (Incident Response and Business Continuity) and recovery plans (Incident Recovery and Disaster Recovery) are in place and managed33
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό PR.IP-10: Response and recovery plans are tested11
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό RC.IM-1: Recovery plans incorporate lessons learned
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό RS.IM-1: Response plans incorporate lessons learned
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό CP-2 Contingency Plan81
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό IR-8 Incident Response Plan1
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό PL-2 System Security and Privacy Plans3
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό SR-2 Supply Chain Risk Management Plan1

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags

Policies (3)​

PolicyLogic CountFlags
πŸ“ AWS S3 Bucket Versioning is not enabled 🟒1🟒 x6
πŸ“ Azure PostgreSQL Flexible Server connection_throttle.enable Parameter is not set to ON 🟒1🟒 x6
πŸ“ Azure Storage Blob Containers Soft Delete is not enabled 🟒1🟒 x6