Skip to main content

💼 RS.MA-03: Incidents are categorized and prioritized

  • Contextual name: 💼 RS.MA-03: Incidents are categorized and prioritized
  • ID: /frameworks/nist-csf-v2.0/rs-ma/03
  • Located in: 💼 Incident Management (RS.MA)

Description

  1. Further review and categorize incidents based on the type of incident (e.g., data breach, ransomware, DDoS, account compromise)
  2. Prioritize incidents based on their scope, likely impact, and time-critical nature
  3. Select incident response strategies for active incidents by balancing the need to quickly recover from an incident with the need to observe the attacker or conduct a more thorough investigation

Similar

  • Sections
    • /frameworks/nist-csf-v1.1/rs-an/04
    • /frameworks/nist-csf-v1.1/rs-an/02
    • /frameworks/nist-sp-800-53-r5/ir/04
    • /frameworks/nist-sp-800-53-r5/ir/05
    • /frameworks/nist-sp-800-53-r5/ir/06

Similar Sections (Take Policies From)

SectionSub SectionsInternal RulesPoliciesFlags
💼 NIST CSF v1.1 → 💼 RS.AN-2: The impact of the incident is understood
💼 NIST CSF v1.1 → 💼 RS.AN-4: Incidents are categorized consistent with response plans
💼 NIST SP 800-53 Revision 5 → 💼 IR-4 Incident Handling15
💼 NIST SP 800-53 Revision 5 → 💼 IR-5 Incident Monitoring1
💼 NIST SP 800-53 Revision 5 → 💼 IR-6 Incident Reporting31

Sub Sections

SectionSub SectionsInternal RulesPoliciesFlags

Policies (1)

PolicyLogic CountFlags
📝 Google Organization Essential Contacts is not configured 🟢1🟢 x6