Skip to main content

πŸ’Ό IR-6 Incident Reporting

  • Contextual name: πŸ’Ό IR-6 Incident Reporting
  • ID: /frameworks/nist-sp-800-53-r5/ir/06
  • Located in: πŸ’Ό IR Incident Response

Description​

a. Require personnel to report suspected incidents to the organizational incident response capability within [Assignment: organization-defined time period]; and b. Report incident information to [Assignment: organization-defined authorities].

Similar​

  • Internal
    • ID: dec-c-cd711b7c

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό FedRAMP High Security Controls β†’ πŸ’Ό IR-6 Incident Reporting (L)(M)(H)21012
πŸ’Ό FedRAMP Low Security Controls β†’ πŸ’Ό IR-6 Incident Reporting (L)(M)(H)
πŸ’Ό NIST CSF v2.0 β†’ πŸ’Ό RC.CO-03: Recovery activities and progress in restoring operational capabilities are communicated to designated internal and external stakeholders
πŸ’Ό NIST CSF v2.0 β†’ πŸ’Ό RS.AN-06: Actions performed during an investigation are recorded, and the records' integrity and provenance are preserved
πŸ’Ό NIST CSF v2.0 β†’ πŸ’Ό RS.AN-07: Incident data and metadata are collected, and their integrity and provenance are preserved
πŸ’Ό NIST CSF v2.0 β†’ πŸ’Ό RS.AN-08: An incident's magnitude is estimated and validated
πŸ’Ό NIST CSF v2.0 β†’ πŸ’Ό RS.CO-02: Internal and external stakeholders are notified of incidents30
πŸ’Ό NIST CSF v2.0 β†’ πŸ’Ό RS.CO-03: Information is shared with designated internal and external stakeholders17
πŸ’Ό NIST CSF v2.0 β†’ πŸ’Ό RS.MA-01: The incident response plan is executed in coordination with relevant third parties once an incident is declared
πŸ’Ό NIST CSF v2.0 β†’ πŸ’Ό RS.MA-02: Incident reports are triaged and validated22
πŸ’Ό NIST CSF v2.0 β†’ πŸ’Ό RS.MA-03: Incidents are categorized and prioritized
πŸ’Ό NIST CSF v2.0 β†’ πŸ’Ό RS.MA-04: Incidents are escalated or elevated as needed

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό IR-6(1) Incident Reporting _ Automated Reporting
πŸ’Ό IR-6(2) Incident Reporting _ Vulnerabilities Related to Incidents
πŸ’Ό IR-6(3) Incident Reporting _ Supply Chain Coordination