Frameworks / FedRAMP High / IR-4 FedRAMP High
IR - Incident Response
FedRAMP High IR-4: Incident Handling Implement IR capability for preparation, detection/analysis, containment, eradication, recovery.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 135 controls across 68 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-DE.AE-04 The estimated impact and scope of adverse events are understood NIST-CSF-ID.IM-03 Improvements are identified from execution of operational processes, procedures, and activities NIST-CSF-PR.PS-04 Log records are generated and made available for continuous monitoring NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process NIST-CSF-RS.AN-03 Analysis is performed to establish what has taken place during an incident and the root cause of the incident NIST-CSF-RS.AN-08 An incident's magnitude is estimated and validated NIST-CSF-RS.MA-01 The incident response plan is executed in coordination with relevant third parties once an incident is declared NIST-CSF-RS.MA-03 Incidents are categorized and prioritized NIST-CSF-RS.MI-01 Incidents are contained NIST-CSF-RS.MI-02 Incidents are eradicated 10.4.3 10.4.3 Exceptions and anomalies from log review addressed 10.7.3 10.7.3 Respond promptly to critical security control failures 12.10.1 12.10.1 Incident response plan ready for activation 12.10.5 12.10.5 Plan covers alerts from security monitoring systems 12.10.6 12.10.6 Plan evolved from lessons learned and industry developments 12.10.7 12.10.7 Response procedures for PAN found in unexpected locations ASBv3-IR-1 Preparation - update incident response plan and handling process ASBv3-IR-4 Detection and analysis - investigate an incident ASBv3-IR-5 Detection and analysis - prioritize incidents ASBv3-IR-6 Containment, eradication and recovery - automate the incident handling ASBv3-IR-7 Post-incident activity - conduct lesson learned and retain evidence CIS-17.1 Designate Personnel to Manage Incident Handling CIS-17.4 Establish and Maintain an Incident Response Process CIS-17.6 Define Mechanisms for Communicating During Incident Response CIS-17.7 Conduct Routine Incident Response Exercises CIS-17.8 Conduct Post-Incident Reviews 5.24 Information security incident management planning and preparation 5.25 Assessment and decision on information security events 5.26 Response to information security incidents 5.27 Learning from information security incidents 5.28 Collection of evidence ASD37-28 Continuous incident detection and response (Excellent) ASD37-29 Host-based IDS/IPS (Very Good) ASD37-30 Endpoint detection and response (Very Good) ASD37-32 Network-based IDS/IPS (Limited) 5.24 Information security incident management planning and preparation 5.25 Assessment and decision on information security events 5.26 Response to information security incidents 5.27 Learning from information security incidents SOC2-CC7.3 CC7.3 Evaluating security events to identify incidents SOC2-CC7.4 CC7.4 Responding to security incidents SOC2-CC7.5 CC7.5 Recovering from security incidents SOC2-P6.6 P6.6 Notifying breaches and incidents CPS234-30 Detection and Response Mechanisms CPS234-P25 Response Plan Content and Escalation Mechanisms E8-APP-ML2 Application Control (ML2) ANSSI-HYG-40 Define a Security Incident Management Procedure CBPR-PR-32 Detection, prevention and response measures API1164-13 Business Continuity and Recovery APPI-A26 Report of Leakage to the Commission and Notification to the Person CPS230-27 Identification and Escalation of Incidents and Near Misses AT-DSG-6 Sections 12-13 - Image processing (video surveillance/CCTV) BSI-17 Continuous monitoring strategy CFTC-SS-16 Security Incident Response Plan and Testing CAT-D3-2 Detective controls FDBR-Enforcement-AG-CurePeriod Enforcement by Florida Department of Legal Affairs + Penalties + 45-Day Cure (Fla. Stat. 501.72, 501.721, 501.722) GDPR-Art.33 Notification of a personal data breach to the supervisory authority ICP-24 Macroprudential Surveillance and Insurance Supervision IEC62443-13 Network security monitoring 6.13.1 Management of information security incidents and improvements ISO28001-PS-01 Facility Security 27006-9.4 Surveillance and recertification ISO27019-13 Network security monitoring 27400-6.5 Security monitoring and incident response JP-FSA-CYB-Security-Monitoring-SOC-Operations-SIEM-EDR-MDR-XDR-24x7-Detection-Alert-Triage Japan FSA Cybersecurity Security Monitoring + SOC 24x7 Operations + SIEM + EDR + MDR + XDR + Detection + Alert Triage + Threat Hunting + Incident Response Integration + Threat Intelligence Integration + UEBA MTCS-Logging-Monitoring-Compliance-Audit-SLA-Configuration-SIEM-SOAR-Cloud-Monitoring-CSPM MTCS Logging + Monitoring + Compliance + Audit + SLA + Configuration + SIEM + SOAR + CSPM NERCCIP-5 System Security Management + Configuration Change Management and Vulnerability Assessments (CIP-007 + CIP-010) NISTSP144-8 Monitoring, Incident Response, Exit Strategy, and Compliance NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition 3.6.2e Establish and Maintain a Cyber Incident Response Team IR-4 IR-4 Incident Handling IR-4 IR-4 Incident Handling IR-4 IR-4 Incident Handling NISTSP82-6 OT Audit, Monitoring, Anomaly Detection, and OT-Specific SOC NZISM-5 Network Security, System Hardening, and Application Security OMANCS-6 Security Monitoring, Detection, Incident Response, and OmanCERT Notification IM8-SEC.3 Network Security ISMSP-SYS-03 Security Monitoring and Log Management TSAPIPE-2 OT/IT Network Segmentation and Access Control CE-SC.8 Process for Compromised Passwords UK-TSA-MON-01 Security Monitoring US-SEC-DA-SC-03 ETF Framework Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in IR - Incident Response You are reading one control. How much of FedRAMP High have you already done? FedRAMP High IR-4 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of FedRAMP High your existing evidence covers. Hold C5 (Germany) and 119 of 410 FedRAMP High controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 6 were rejected on the C5 (Germany) pair alone.
Query this from an agent The graph holds this control, the 135 it maps to, and the evidence behind each claim, over MCP and REST.