Frameworks / FedRAMP Moderate / IR-8 What else in your programme already covers this This control maps to 61 controls across 32 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
CIS-17.1 Designate Personnel to Manage Incident Handling CIS-17.3 Establish and Maintain an Enterprise Process for Reporting Incidents CIS-17.4 Establish and Maintain an Incident Response Process CIS-17.5 Assign Key Roles and Responsibilities CIS-17.6 Define Mechanisms for Communicating During Incident Response CIS-17.7 Conduct Routine Incident Response Exercises CIS-17.8 Conduct Post-Incident Reviews CIS-17.9 Establish and Maintain Security Incident Thresholds NIST-CSF-DE.AE-08 Incidents are declared when adverse events meet the defined incident criteria NIST-CSF-ID.IM-04 Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved NIST-CSF-RS.MA-01 The incident response plan is executed in coordination with relevant third parties once an incident is declared NIST-CSF-RS.MA-03 Incidents are categorized and prioritized SOC2-CC2.2 CC2.2 Internal communication of objectives and control responsibilities (COSO principle 14) SOC2-CC7.3 CC7.3 Evaluating security events to identify incidents SOC2-CC7.4 CC7.4 Responding to security incidents SOC2-CC7.5 CC7.5 Recovering from security incidents CPS234-32 Annual Review and Testing of Response Plans CPS234-P24 Information Security Response Plans CPS234-P25 Response Plan Content and Escalation Mechanisms SEC10-BP01 Identify key personnel and external resources SEC10-BP02 Develop incident management plans SEC10-BP04 Develop and test security incident response playbooks 12.10.1 12.10.1 Incident response plan ready for activation 12.10.2 12.10.2 Annual review and testing of the incident response plan 12.10.5 12.10.5 Plan covers alerts from security monitoring systems C5-OPS-21 Involvement of Cloud Customers in the Event of Incidents C5-SIM-01 Policy for security incident management 8.4.2 Response structure 8.4.4 Business continuity plans 5.24 Information security incident management planning and preparation 5.26 Response to information security incidents 5.24 Information security incident management planning and preparation 5.26 Response to information security incidents Art.21.2.b Incident handling Art.23.1 Notify significant incidents to the CSIRT or competent authority, and warn affected service recipients ANSSI-HYG-40 Define a Security Incident Management Procedure APPI-A26 Report of Leakage to the Commission and Notification to the Person CPS230-27 Identification and Escalation of Incidents and Near Misses ASBv3-IR-1 Preparation - update incident response plan and handling process CFTC-SS-16 Security Incident Response Plan and Testing GDPR-Art.33 Notification of a personal data breach to the supervisory authority 6.13.1 Management of information security incidents and improvements A.8.4 Communication of incidents IR-8 IR-8 Incident Response Plan IR-8 IR-8 Incident Response Plan IR-8 IR-8 Incident Response Plan Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in IR - Incident Response You are reading one control. How much of FedRAMP Moderate have you already done? FedRAMP Moderate IR-8 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of FedRAMP Moderate your existing evidence covers. Hold ISO 27002:2022 and 182 of 323 FedRAMP Moderate controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 348 were rejected on the ISO 27002:2022 pair alone.
Query this from an agent The graph holds this control, the 61 it maps to, and the evidence behind each claim, over MCP and REST.