Skip to main content

πŸ’Ό RS.MA-03: Incidents are categorized and prioritized

  • Contextual name: πŸ’Ό RS.MA-03: Incidents are categorized and prioritized
  • ID: /frameworks/nist-csf-v2.0/rs-ma/03
  • Located in: πŸ’Ό Incident Management (RS.MA)

Description​

  1. Further review and categorize incidents based on the type of incident (e.g., data breach, ransomware, DDoS, account compromise)
  2. Prioritize incidents based on their scope, likely impact, and time-critical nature
  3. Select incident response strategies for active incidents by balancing the need to quickly recover from an incident with the need to observe the attacker or conduct a more thorough investigation

Similar​

  • Sections
    • /frameworks/nist-csf-v1.1/rs-an/04
    • /frameworks/nist-csf-v1.1/rs-an/02
    • /frameworks/nist-sp-800-53-r5/ir/04
    • /frameworks/nist-sp-800-53-r5/ir/05
    • /frameworks/nist-sp-800-53-r5/ir/06

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό RS.AN-2: The impact of the incident is understood
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό RS.AN-4: Incidents are categorized consistent with response plans
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό IR-4 Incident Handling15
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό IR-5 Incident Monitoring1
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό IR-6 Incident Reporting3

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags