πΌ IR-4 INCIDENT HANDLING
- Contextual name: πΌ IR-4 INCIDENT HANDLING
- ID:
/frameworks/nist-sp-800-53-r4/ir/04
- Located in: πΌ IR INCIDENT RESPONSE
Descriptionβ
The organization: IR-4a. Implements an incident handling capability for security incidents that includes preparation, detection and analysis, containment, eradication, and recovery; IR-4b. Coordinates incident handling activities with contingency planning activities; and IR-4c. Incorporates lessons learned from ongoing incident handling activities into incident response procedures, training, and testing, and implements the resulting changes accordingly.
Similarβ
- Internal
- ID:
dec-c-2652716b
- ID:
Similar Sections (Give Policies To)β
Section | Sub Sections | Internal Rules | Policies | Flags |
---|---|---|---|---|
πΌ NIST CSF v1.1 β πΌ DE.AE-2: Detected events are analyzed to understand attack targets and methods | 19 | 22 | ||
πΌ NIST CSF v1.1 β πΌ DE.AE-3: Event data are collected and correlated from multiple sources and sensors | 19 | 22 | ||
πΌ NIST CSF v1.1 β πΌ DE.AE-4: Impact of events is determined | 14 | 14 | ||
πΌ NIST CSF v1.1 β πΌ DE.AE-5: Incident alert thresholds are established | ||||