Skip to main content

💼 IR-4 Incident Handling

  • ID: /frameworks/nist-sp-800-53-r5/ir/04

Description​

a. Implement an incident handling capability for incidents that is consistent with the incident response plan and includes preparation, detection and analysis, containment, eradication, and recovery; b. Coordinate incident handling activities with contingency planning activities; c. Incorporate lessons learned from ongoing incident handling activities into incident response procedures, training, and testing, and implement the resulting changes accordingly; and d. Ensure the rigor, intensity, scope, and results of incident handling activities are comparable and predictable across the organization.

Similar​

  • Internal
    • ID: dec-c-7f432267

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 FedRAMP High Security Controls → 💼 IR-4 Incident Handling (L)(M)(H)51no data
💼 FedRAMP Low Security Controls → 💼 IR-4 Incident Handling (L)(M)(H)no data
💼 NIST CSF v2.0 → 💼 DE.AE-02: Potentially adverse events are analyzed to better understand associated activities35no data
💼 NIST CSF v2.0 → 💼 DE.AE-03: Information is correlated from multiple sources50no data
💼 NIST CSF v2.0 → 💼 DE.AE-06: Information on adverse events is provided to authorized staff and tools33no data
💼 NIST CSF v2.0 → 💼 DE.AE-08: Incidents are declared when adverse events meet the defined incident criteriano data
💼 NIST CSF v2.0 → 💼 ID.IM-01: Improvements are identified from evaluations26no data
💼 NIST CSF v2.0 → 💼 ID.IM-02: Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties40no data
💼 NIST CSF v2.0 → 💼 ID.IM-03: Improvements are identified from execution of operational processes, procedures, and activities41no data
💼 NIST CSF v2.0 → 💼 RC.CO-03: Recovery activities and progress in restoring operational capabilities are communicated to designated internal and external stakeholders1no data
💼 NIST CSF v2.0 → 💼 RC.CO-04: Public updates on incident recovery are shared using approved methods and messaging22no data
💼 NIST CSF v2.0 → 💼 RC.RP-01: The recovery portion of the incident response plan is executed once initiated from the incident response process12no data
💼 NIST CSF v2.0 → 💼 RC.RP-02: Recovery actions are selected, scoped, prioritized, and performed12no data
💼 NIST CSF v2.0 → 💼 RC.RP-06: The end of incident recovery is declared based on criteria, and incident-related documentation is completedno data
💼 NIST CSF v2.0 → 💼 RS.AN-03: Analysis is performed to establish what has taken place during an incident and the root cause of the incident17no data
💼 NIST CSF v2.0 → 💼 RS.AN-06: Actions performed during an investigation are recorded, and the records' integrity and provenance are preserved18no data
💼 NIST CSF v2.0 → 💼 RS.AN-07: Incident data and metadata are collected, and their integrity and provenance are preserved18no data
💼 NIST CSF v2.0 → 💼 RS.AN-08: An incident's magnitude is estimated and validated1no data
💼 NIST CSF v2.0 → 💼 RS.CO-02: Internal and external stakeholders are notified of incidents31no data
💼 NIST CSF v2.0 → 💼 RS.CO-03: Information is shared with designated internal and external stakeholders19no data
💼 NIST CSF v2.0 → 💼 RS.MA-02: Incident reports are triaged and validated25no data
💼 NIST CSF v2.0 → 💼 RS.MA-03: Incidents are categorized and prioritized1no data
💼 NIST CSF v2.0 → 💼 RS.MA-04: Incidents are escalated or elevated as needed1no data
💼 NIST CSF v2.0 → 💼 RS.MA-05: The criteria for initiating incident recovery are appliedno data
💼 NIST CSF v2.0 → 💼 RS.MI-01: Incidents are contained7no data
💼 NIST CSF v2.0 → 💼 RS.MI-02: Incidents are eradicated7no data

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 IR-4(1) Incident Handling _ Automated Incident Handling Processes1no data
💼 IR-4(2) Incident Handling _ Dynamic Reconfigurationno data
💼 IR-4(3) Incident Handling _ Continuity of Operationsno data
💼 IR-4(4) Incident Handling _ Information Correlationno data
💼 IR-4(5) Incident Handling _ Automatic Disabling of System1no data
💼 IR-4(6) Incident Handling _ Insider Threatsno data
💼 IR-4(7) Incident Handling _ Insider Threats — Intra-organization Coordinationno data
💼 IR-4(8) Incident Handling _ Correlation with External Organizationsno data
💼 IR-4(9) Incident Handling _ Dynamic Response Capabilityno data
💼 IR-4(10) Incident Handling _ Supply Chain Coordinationno data
💼 IR-4(11) Incident Handling _ Integrated Incident Response Teamno data
💼 IR-4(12) Incident Handling _ Malicious Code and Forensic Analysisno data
💼 IR-4(13) Incident Handling _ Behavior Analysisno data
💼 IR-4(14) Incident Handling _ Security Operations Centerno data
💼 IR-4(15) Incident Handling _ Public Relations and Reputation Repairno data