CMMC 2.0
Incident Response

CMMC 2.0 IR.L2-3.6.1: Incident Handling

Operate an incident handling capability covering preparation, detection, analysis, containment, recovery and user response.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 101 controls across 29 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 22301:2019 · 8 controls

  • 5.3 Roles, responsibilities and authorities
  • 8.4 Business continuity plans and procedures
  • 8.4.1 General
  • 8.4.2 Response structure
  • 8.4.3 Warning and communication
  • 8.4.4 Business continuity plans
  • 8.4.5 Recovery
  • 8.5 Exercise programme

CIS Controls v8 · 7 controls

  • CIS-17.1 Designate Personnel to Manage Incident Handling
  • CIS-17.3 Establish and Maintain an Enterprise Process for Reporting Incidents
  • CIS-17.4 Establish and Maintain an Incident Response Process
  • CIS-17.5 Assign Key Roles and Responsibilities
  • CIS-17.6 Define Mechanisms for Communicating During Incident Response
  • CIS-17.8 Conduct Post-Incident Reviews
  • CIS-17.9 Establish and Maintain Security Incident Thresholds

NIST SP 800-53 Rev 5 · 7 controls

  • ASBv3-GS-7 Define and implement logging, threat detection and incident response strategy
  • ASBv3-IR-1 Preparation - update incident response plan and handling process
  • ASBv3-IR-4 Detection and analysis - investigate an incident
  • ASBv3-IR-5 Detection and analysis - prioritize incidents
  • ASBv3-IR-6 Containment, eradication and recovery - automate the incident handling
  • ASBv3-IR-7 Post-incident activity - conduct lesson learned and retain evidence
  • SEC10-BP01 Identify key personnel and external resources
  • SEC10-BP02 Develop incident management plans
  • SEC10-BP03 Prepare forensic capabilities
  • SEC10-BP04 Develop and test security incident response playbooks
  • SEC10-BP08 Establish a framework for learning from incidents

FedRAMP High · 5 controls

  • IR-4 Incident Handling
  • IR-4(1) Automated Incident Handling Processes
  • IR-5 Incident Monitoring
  • IR-7 Incident Response Assistance
  • IR-8 Incident Response Plan

FedRAMP Moderate · 5 controls

  • IR-4 Incident Handling
  • IR-4(1) Automated Incident Handling Processes
  • IR-5 Incident Monitoring
  • IR-7 Incident Response Assistance
  • IR-8 Incident Response Plan

SOC 2 · 5 controls

  • SOC2-CC7.3 CC7.3 Evaluating security events to identify incidents
  • SOC2-CC7.4 CC7.4 Responding to security incidents
  • SOC2-CC7.5 CC7.5 Recovering from security incidents
  • SOC2-P6.3 P6.3 Record of unauthorised disclosures and breaches
  • SOC2-P6.6 P6.6 Notifying breaches and incidents
  • ASD37-28 Continuous incident detection and response (Excellent)
  • ASD37-30 Endpoint detection and response (Very Good)
  • ASD37-35 Business continuity and disaster recovery plans (Very Good)
  • ASD37-36 System recovery capabilities (Very Good)

ISO 27001:2022 · 4 controls

  • 5.24 Information security incident management planning and preparation 
  • 5.25 Assessment and decision on information security events
  • 5.26 Response to information security incidents
  • 5.27 Learning from information security incidents
  • CPS230-20 Prevention, Adaptation and Return to Normal Operations
  • CPS230-27 Identification and Escalation of Incidents and Near Misses
  • CPS230-P41 BCP Execution Capability and Tolerance Breach Reporting

APRA CPS 234 · 3 controls

  • CPS234-30 Detection and Response Mechanisms
  • CPS234-P24 Information Security Response Plans
  • CPS234-P25 Response Plan Content and Escalation Mechanisms

C5 (Germany) · 3 controls

ISO 27002:2022 · 3 controls

  • 5.24 Information security incident management planning and preparation
  • 5.25 Assessment and decision on information security events
  • 5.26 Response to information security incidents

HIPAA Security Rule · 2 controls

NIST SP 800-171 Rev 3 · 2 controls

NIST SP 800-172 · 2 controls

  • 3.6.1e Establish Security Operations Center (SOC)
  • 3.6.2e Establish and Maintain a Cyber Incident Response Team

NIST SP 800-66 Rev 2 · 2 controls

PCI DSS 4.0 · 2 controls

  • 10.7.3 10.7.3 Respond promptly to critical security control failures
  • 12.10.1 12.10.1 Incident response plan ready for activation
  • E8-APP-ML2 Application Control (ML2)
  • ANSSI-HYG-40 Define a Security Incident Management Procedure
  • AEO-12 Crisis Management and Incident Recovery
  • CFTC-SS-16 Security Incident Response Plan and Testing

ISO 27701:2019 · 1 control

  • 6.13.1 Management of information security incidents and improvements

NIS2 Directive · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Incident Response

You are reading one control. How much of CMMC 2.0 have you already done?

CMMC 2.0 IR.L2-3.6.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of CMMC 2.0 your existing evidence covers. Hold FedRAMP Moderate and 108 of 110 CMMC 2.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 1 were rejected on the FedRAMP Moderate pair alone.

Query this from an agent

The graph holds this control, the 101 it maps to, and the evidence behind each claim, over MCP and REST.