Frameworks / FedRAMP Moderate / IR-4 FedRAMP Moderate
IR - Incident Response
FedRAMP Moderate IR-4: Incident Handling Implement IR capability for preparation, detection/analysis, containment, eradication, recovery.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 135 controls across 69 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-DE.AE-04 The estimated impact and scope of adverse events are understood NIST-CSF-ID.IM-03 Improvements are identified from execution of operational processes, procedures, and activities NIST-CSF-PR.PS-04 Log records are generated and made available for continuous monitoring NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process NIST-CSF-RS.AN-03 Analysis is performed to establish what has taken place during an incident and the root cause of the incident NIST-CSF-RS.AN-08 An incident's magnitude is estimated and validated NIST-CSF-RS.MA-01 The incident response plan is executed in coordination with relevant third parties once an incident is declared NIST-CSF-RS.MA-03 Incidents are categorized and prioritized NIST-CSF-RS.MI-01 Incidents are contained NIST-CSF-RS.MI-02 Incidents are eradicated 10.4.3 Exceptions and anomalies addressed 10.7.3 Failure response timeline 12.10.1 Incident response plan 12.10.5 IRP includes monitoring and response to security control alerts 12.10.6 IRP refined based on lessons learned 12.10.7 Response procedures for PAN detection in unexpected locations ASBv3-IR-1 Preparation - update incident response plan and handling process ASBv3-IR-4 Detection and analysis - investigate an incident ASBv3-IR-5 Detection and analysis - prioritize incidents ASBv3-IR-6 Containment, eradication and recovery - automate the incident handling ASBv3-IR-7 Post-incident activity - conduct lesson learned and retain evidence CIS-17.1 Designate Personnel to Manage Incident Handling CIS-17.4 Establish and Maintain an Incident Response Process CIS-17.6 Define Mechanisms for Communicating During Incident Response CIS-17.7 Conduct Routine Incident Response Exercises CIS-17.8 Conduct Post-Incident Reviews 5.24 Information security incident management planning and preparation 5.25 Assessment and decision on information security events 5.26 Response to information security incidents 5.27 Learning from information security incidents 5.28 Collection of evidence ASD37-28 Continuous incident detection and response (Excellent) ASD37-29 Host-based IDS/IPS (Very Good) ASD37-30 Endpoint detection and response (Very Good) ASD37-32 Network-based IDS/IPS (Limited) 5.24 Information security incident management planning and preparation 5.25 Assessment and decision on information security events 5.26 Response to information security incidents 5.27 Learning from information security incidents SOC2-CC7.3 Evaluates security events to determine incident status SOC2-CC7.4 Responds to identified security incidents through defined procedures SOC2-CC7.5 Identifies the root cause of security incidents SOC2-P6.6 Provides notification of breaches and incidents to affected data subjects, regulators, and others to meet the entity's objectives related to privacy CPS234-30 Detection and Response Mechanisms CPS234-P25 Response Plan Content and Escalation Mechanisms ANSSI-HYG-40 Define a Security Incident Management Procedure CBPR-PR-32 Detection, prevention and response measures APPI-A26 Report of Leakage to the Commission and Notification to the Person CPS230-27 Identification and Escalation of Incidents and Near Misses AT-DSG-6 Sections 12-13 - Image processing (video surveillance/CCTV) BSI-17 Continuous monitoring strategy CFTC-SS-16 Security Incident Response Plan and Testing GDPR-Art.33 Notification of a personal data breach to the supervisory authority ICP-24 Macroprudential Surveillance and Insurance Supervision 6.13.1 Management of information security incidents and improvements 27400-6.5 Security monitoring and incident response NERCCIP-5 System Security Management + Configuration Change Management and Vulnerability Assessments (CIP-007 + CIP-010) NISTSP144-8 Monitoring, Incident Response, Exit Strategy, and Compliance NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition 3.12 Segment Data Processing and Storage Based on Sensitivity 3.6.2e Establish and Maintain a Cyber Incident Response Team NISTSP82-6 OT Audit, Monitoring, Anomaly Detection, and OT-Specific SOC NZISM-5 Network Security, System Hardening, and Application Security OMANCS-6 Security Monitoring, Detection, Incident Response, and OmanCERT Notification TSAPIPE-2 OT/IT Network Segmentation and Access Control CE-SC.8 Process for Compromised Passwords Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in IR - Incident Response You are reading one control. How much of FedRAMP Moderate have you already done? FedRAMP Moderate IR-4 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of FedRAMP Moderate your existing evidence covers. Hold ISO 27002:2022 and 182 of 323 FedRAMP Moderate controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 348 were rejected on the ISO 27002:2022 pair alone.
Query this from an agent The graph holds this control, the 135 it maps to, and the evidence behind each claim, over MCP and REST.