AWS Well-Architected Security Pillar
Incident Response

AWS Well-Architected Security Pillar SEC10-BP08: Establish a framework for learning from incidents

Run blameless post-incident reviews, capture root causes and contributing factors, and feed improvements back into controls, runbooks and training.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 40 controls across 22 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

C5 (Germany) · 3 controls

  • C5-OPS-20 Managing Vulnerabilities, Malfunctions and Errors - Measurements, Analyses and Assessments of Procedures
  • C5-SIM-03 Documentation and reporting of security incidents
  • C5-SIM-05 Evaluation and learning process

NIST SP 800-218 · 3 controls

CIS Controls v8 · 2 controls

  • CIS-16.3 Perform Root Cause Analysis on Security Vulnerabilities
  • CIS-17.8 Conduct Post-Incident Reviews

CMMC 2.0 · 2 controls

FedRAMP High · 2 controls

  • IR-4 Incident Handling
  • IR-5 Incident Monitoring

FedRAMP Moderate · 2 controls

  • IR-4 Incident Handling
  • IR-5 Incident Monitoring
  • NIST-CSF-ID.IM-03 Improvements are identified from execution of operational processes, procedures, and activities
  • NIST-CSF-RS.AN-08 An incident's magnitude is estimated and validated

NIST SP 800-161 Rev 1 · 2 controls

NIST SP 800-171 Rev 3 · 2 controls

  • 03.06.01 Incident Handling
  • 03.06.02 Incident Monitoring, Reporting, and Response Assistance

NIST SP 800-53 Rev 5 · 2 controls

  • IR-4 Incident Handling
  • IR-5 Incident Monitoring
  • IR-4 Incident Handling
  • IR-5 Incident Monitoring
  • IR-4 Incident Handling
  • IR-5 Incident Monitoring

PCI DSS 4.0 · 2 controls

  • 10.7.3 Failure response timeline
  • 12.10.6 IRP refined based on lessons learned
  • ANSSI-HYG-40 Define a Security Incident Management Procedure
  • ASBv3-IR-7 Post-incident activity - conduct lesson learned and retain evidence

HIPAA Security Rule · 1 control

ISO 27001:2022 · 1 control

  • 5.27 Learning from information security incidents

ISO 27002:2022 · 1 control

  • 5.27 Learning from information security incidents

SOC 2 · 1 control

  • SOC2-CC7.5 Identifies the root cause of security incidents

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Incident Response

You are reading one control. How much of AWS Well-Architected Security Pillar have you already done?

AWS Well-Architected Security Pillar SEC10-BP08 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of AWS Well-Architected Security Pillar your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 52 of 63 AWS Well-Architected Security Pillar controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 40 it maps to, and the evidence behind each claim, over MCP and REST.