Skip to main content

πŸ’Ό RS.MI-01: Incidents are contained

  • Contextual name: πŸ’Ό RS.MI-01: Incidents are contained
  • ID: /frameworks/nist-csf-v2.0/rs-mi/01
  • Located in: πŸ’Ό Incident Mitigation (RS.MI)

Description​

  1. Cybersecurity technologies (e.g., antivirus software) and cybersecurity features of other technologies (e.g., operating systems, network infrastructure devices) automatically perform containment actions
  2. Allow incident responders to manually select and perform containment actions
  3. Allow a third party (e.g., internet service provider, managed security service provider) to perform containment actions on behalf of the organization
  4. Automatically transfer compromised endpoints to a remediation virtual local area network (VLAN)

Similar​

  • Sections
    • /frameworks/nist-csf-v1.1/rs-mi/01
    • /frameworks/nist-sp-800-53-r5/ir/04

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό RS.MI-1: Incidents are contained77
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό IR-4 Incident Handling15

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags

Policies (7)​

PolicyLogic CountFlags
πŸ“ Azure Subscription Microsoft Defender For (Managed Instance) Azure SQL Databases is not set to On 🟒1🟒 x6
πŸ“ Azure Subscription Microsoft Defender For App Services is not set to On 🟒1🟒 x6
πŸ“ Azure Subscription Microsoft Defender For Containers is not set to On 🟒1🟒 x6
πŸ“ Azure Subscription Microsoft Defender For Key Vault is not set to On 🟒1🟒 x6
πŸ“ Azure Subscription Microsoft Defender For Servers is not set to On 🟒1🟒 x6
πŸ“ Azure Subscription Microsoft Defender For SQL Servers On Machines is not set to On 🟒1🟒 x6
πŸ“ Azure Subscription Microsoft Defender For Storage is not set to On 🟒1🟒 x6