Skip to main content

πŸ’Ό RS.AN-03: Analysis is performed to establish what has taken place during an incident and the root cause of the incident

  • Contextual name: πŸ’Ό RS.AN-03: Analysis is performed to establish what has taken place during an incident and the root cause of the incident
  • ID: /frameworks/nist-csf-v2.0/rs-an/03
  • Located in: πŸ’Ό Incident Analysis (RS.AN)

Description​

  1. Determine the sequence of events that occurred during the incident and which assets and resources were involved in each event
  2. Attempt to determine what vulnerabilities, threats, and threat actors were directly or indirectly involved in the incident
  3. Analyze the incident to find the underlying, systemic root causes
  4. Check any cyber deception technology for additional information on attacker behavior

Similar​

  • Sections
    • /frameworks/nist-csf-v1.1/rs-an/03
    • /frameworks/nist-sp-800-53-r5/au/07
    • /frameworks/nist-sp-800-53-r5/ir/04

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό RS.AN-3: Forensics are performed
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό AU-7 Audit Record Reduction and Report Generation211
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό IR-4 Incident Handling15

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags