FedRAMP High
IR - Incident Response

FedRAMP High IR-6: Incident Reporting

Require personnel to report incidents to organizational authorities within FedRAMP timeframe; report to FedRAMP PMO and US-CERT.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 56 controls across 31 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27002:2022 · 5 controls

  • 5.24 Information security incident management planning and preparation
  • 5.26 Response to information security incidents
  • 5.28 Collection of evidence
  • 5.5 Contact with authorities
  • 6.8 Information security event reporting

C5 (Germany) · 4 controls

  • C5-OIS-05 Contact with Relevant Government Agencies and Interest Groups
  • C5-OPS-21 Involvement of Cloud Customers in the Event of Incidents
  • C5-SIM-03 Documentation and reporting of security incidents
  • C5-SIM-04 Duty of the users to report security incidents to a central body

CIS Controls v8 · 4 controls

  • CIS-14.6 Train Workforce Members on Recognizing and Reporting Security Incidents
  • CIS-17.1 Designate Personnel to Manage Incident Handling
  • CIS-17.2 Establish and Maintain Contact Information for Reporting Security Incidents
  • CIS-17.3 Establish and Maintain an Enterprise Process for Reporting Incidents

ISO 27001:2022 · 4 controls

  • 5.24 Information security incident management planning and preparation
  • 5.26 Response to information security incidents
  • 5.5 Contact with authorities
  • 6.8 Information security event reporting
  • NIST-CSF-RC.CO-03 Recovery activities and progress in restoring operational capabilities are communicated to designated internal and external stakeholders
  • NIST-CSF-RC.CO-04 Public updates on incident recovery are shared using approved methods and messaging
  • NIST-CSF-RS.CO-02 Internal and external stakeholders are notified of incidents
  • NIST-CSF-RS.CO-03 Information is shared with designated internal and external stakeholders
  • CPS230-27 Identification and Escalation of Incidents and Near Misses
  • CPS230-P33 APRA Notification of Operational Risk Incidents within 72 Hours
  • CPS230-P42 APRA Notification of Disruption Outside Tolerance within 24 Hours

DORA · 3 controls

SOC 2 · 3 controls

  • SOC2-CC2.3 COSO principle 15: Communicates with external parties regarding matters affecting controls
  • SOC2-CC7.4 Responds to identified security incidents through defined procedures
  • SOC2-P6.6 Provides notification of breaches and incidents to affected data subjects, regulators, and others to meet the entity's objectives related to privacy
  • ANSSI-HYG-40 Define a Security Incident Management Procedure

APPI · 1 control

  • APPI-A26 Report of Leakage to the Commission and Notification to the Person
  • CPS220-19 APRA Notification of Framework Breach within 10 Business Days

APRA CPS 234 · 1 control

  • CPS234-35 APRA Notification of Material Incidents within 72 Hours
  • ASBv3-IR-2 Preparation - setup incident notification

CMMC 2.0 · 1 control

GDPR · 1 control

  • GDPR-Art.33 Notification of a personal data breach to the supervisory authority

HIPAA Security Rule · 1 control

ISO 22301:2019 · 1 control

  • 8.4.3 Warning and communication

ISO 27701:2019 · 1 control

  • 6.13.1 Management of information security incidents and improvements

ISO/IEC 42001:2023 · 1 control

  • A.8.4 Communication of incidents

NIS2 Directive · 1 control

  • Art.23.1 Notify significant incidents to the CSIRT or competent authority, and warn affected service recipients
  • 03.06.02 Incident Monitoring, Reporting, and Response Assistance

PCI DSS 4.0 · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in IR - Incident Response

You are reading one control. How much of FedRAMP High have you already done?

FedRAMP High IR-6 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of FedRAMP High your existing evidence covers. Hold C5 (Germany) and 119 of 410 FedRAMP High controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 6 were rejected on the C5 (Germany) pair alone.

Query this from an agent

The graph holds this control, the 56 it maps to, and the evidence behind each claim, over MCP and REST.