IEC 62443
IEC 62443: Incident Response & Recovery

IEC 62443 IEC62443-16: Incident response plan for operational disruptions

Incident response plan for operational disruptions. Control from IEC 62443 framework, domain: IEC 62443: Incident Response & Recovery.

What else in your programme already covers this

This control maps to 313 controls across 144 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • ASD37-31 Hunt to discover incidents (Very Good)
  • ASD37-33 Capture network traffic (Limited)
  • ASD37-34 Regular backups (Essential)
  • ASD37-35 Business continuity and disaster recovery plans (Very Good)
  • ASD37-36 System recovery capabilities (Very Good)
  • NIST-CSF-ID.IM-04 Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved
  • NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process
  • NIST-CSF-RC.RP-06 The end of incident recovery is declared based on criteria, and incident-related documentation is completed
  • NIST-CSF-RS.MA-01 The incident response plan is executed in coordination with relevant third parties once an incident is declared
  • NIST-CSF-RS.MA-05 The criteria for initiating incident recovery are applied

NIST SP 800-53 Rev 5 · 5 controls

  • FFIEC-12 Disaster recovery procedures
  • FFIEC-23 Regulatory reporting requirements
  • FFIEC-24 Customer notification procedures
  • FFIEC-25 Post-incident review and improvement
  • NDPA-1 Applicability, Scope, and Carve-Outs
  • NDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • NDPA-5 Privacy Notice, Data Minimisation, and Purpose Limitation
  • NDPA-6 Reasonable Security Practices and Incident Response
  • NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission
  • NG-NDPA-2 Lawful Basis, Consent, and Data Protection Principles
  • NG-NDPA-5 Security of Processing, Breach Notification, and DPIA
  • NG-NDPA-6 Data Protection Officer, DPCO, and Processor Agreements

PCI P2PE · 4 controls

PCI PIN Security · 4 controls

PCI SSF · 4 controls

SOC 2 · 4 controls

  • SOC2-A1.2 Environmental protections, data backups, and recovery infrastructure support availability
  • SOC2-A1.3 Recovery plan procedures support system recovery from failures
  • SOC2-CC7.4 Responds to identified security incidents through defined procedures
  • SOC2-CC7.5 Identifies the root cause of security incidents

API 1164 · 3 controls

BSI IT-Grundschutz · 3 controls

  • BSI-18 Incident response planning and testing
  • BSI-20 Incident reporting and notification
  • BSI-21 Forensic analysis capabilities

ISO 22320:2018 · 3 controls

ISO 27019 · 3 controls

ISO/IEC 27031:2011 · 3 controls

MTCS (Singapore) · 3 controls

NIST SP 1800-32 · 3 controls

  • 3.6 Encrypt Data on End-User Devices
  • 3.6.1 Procedures are defined and implemented to protect cryptographic keys used to protect stored account data against disclosure and misuse that include: • Access to keys is restricted to the fewest number of custodians necessary.
  • FEDRAMP-CP-9 System Backup

OSFI B-13 · 3 controls

  • OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery
  • OSFIB13-7 Incident Reporting to OSFI and Regulatory Coordination
  • OSFIB13-8 Metrics, Monitoring, Continuous Improvement, Maturity

PSD2 SCA · 3 controls

  • PSDTWO-2 SCA Exemptions and Risk-Based Authentication
  • PSDTWO-3 Common and Secure Communication, API Access for AISPs and PISPs
  • PSDTWO-4 Fraud Reporting and Incident Management

South Korea ISMS-P · 3 controls

  • D.1 Incident Response Planning
  • D.2 Incident Reporting
  • D.3 Backup and Recovery

APPI · 2 controls

  • APPI-A41 Preparation and Handling of Pseudonymized Personal Information
  • APPI-A43 Preparation of Anonymized Personal Information

APRA CPS 234 · 2 controls

  • CPS234-21 Implementation of Information Security Controls
  • CPS234-25 Internal Audit Review of Information Security Controls
  • 4.4.7 Emergency and Incident Response
  • 4.4.8 Business Continuity and Recovery

Bahrain PDPL · 2 controls

ISMAP (Japan) · 2 controls

ISO 22316 · 2 controls

ISO 22317 · 2 controls

ISO 22318 · 2 controls

ISO 27017 · 2 controls

ISO 27018 · 2 controls

ISO/IEC 30111:2019 · 2 controls

Malaysia PDPA 2010 · 2 controls

NIST SP 800-144 · 2 controls

  • NISTSP144-6 Availability, Resilience, BCP/DR, and SLA Management
  • NISTSP144-8 Monitoring, Incident Response, Exit Strategy, and Compliance

NIST SP 800-145 · 2 controls

  • NISTSP145-3 Rapid Elasticity Characteristic and Capacity Management
  • NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition

NIST SP 800-146 · 2 controls

  • NISTSP146-6 Cloud Security and Privacy Recommendations
  • NISTSP146-7 Service Level, Performance, Reliability, Interoperability, and Portability

NIST SP 800-190 · 2 controls

  • NJDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • NJDPA-6 Reasonable Data Security and Incident Response
  • OMANCS-6 Security Monitoring, Detection, Incident Response, and OmanCERT Notification
  • OMANCS-7 Business Continuity, Disaster Recovery, and Resilience

Open Banking Security · 2 controls

  • OPENBANK-7 Logging, Monitoring, Regulatory Reporting, SLA, Availability
  • OPENBANK-8 Incident Detection, Response, Customer Notification, Post-Incident Review, BCM

Peru DPL · 2 controls

  • PERU-7 DPO, Records, Retention, Marketing, Training
  • PERU-8 Breach Notification, ANPD Cooperation, Sanctions, Compliance

Qatar DPL · 2 controls

  • QATAR-5 Security of Processing
  • QATAR-8 Breach Notification, Compliance, Enforcement

Saudi Arabia PDPL · 2 controls

South Korea PIPA · 2 controls

  • PMF-M.4 Privacy Incident Management
  • CPS230-13 Board Accountability for Operational Risk Management
  • BB-DPA-20 Sections 50-60 - Registration and Responsibilities
  • CA-12 Deploys Through Policies and Procedures
  • DIQ-1 Data Integration and Interoperability

IEEE 1686 · 1 control

ISO 20000-1 · 1 control

ISO 27043 · 1 control

ISO/IEC 27010:2015 · 1 control

ISO/IEC 27011:2024 · 1 control

ISO/IEC 27400:2022 · 1 control

  • 27400-6.5 Security monitoring and incident response

ISO/IEC 29147:2018 · 1 control

ISO/SAE 21434 · 1 control

ITIL 4 · 1 control

LGPD · 1 control

Liechtenstein DPA · 1 control

MITRE ATT&CK · 1 control

Mauritius DPA · 1 control

Mexico LFPDPPP · 1 control

  • NAIC-5 Third Party Service Provider Oversight - Section 4(F)(3) and Section 5

NERC CIP · 1 control

  • NERCCIP-6 Incident Reporting and Response Planning + Recovery Plans (CIP-008 + CIP-009)
  • NIS2I-3 Incident Handling Policy, Reporting Significance Criteria, and Business Continuity
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)
  • NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material

NIST SP 800-122 · 1 control

NIST SP 800-123 · 1 control

  • NISTSP123-5 Server Operations - Patching, Malware, Logging, Backup

NIST SP 800-137 · 1 control

  • NISTSP137-7 Incident Response Integration and Ongoing Authorization

NIST SP 800-171 · 1 control

  • 3.6.1 Procedures are defined and implemented to protect cryptographic keys used to protect stored account data against disclosure and misuse that include: • Access to keys is restricted to the fewest number of custodians necessary.

NIST SP 800-61 · 1 control

NIST SP 800-63-4 · 1 control

  • NISTSP63R4-4 Authenticator Lifecycle: Binding, Recovery, Replacement, Suspension, Revocation
  • NISTSP82-7 OT Incident Response, Forensics, Recovery, and Continuity

NIST SP 800-88 · 1 control

  • NISTSP88-5 Media Inventory, Tracking, Chain of Custody, and Sanitization Records

NIST SP 800-92 · 1 control

  • NISTSP92-6 Log Retention: Policy, Tiered Storage, Backup, Secure Disposal, Legal Hold
  • NRFCS-7 Detection, Logging, Incident Response, Breach Notification, and Fraud Detection
  • NGCB-6 Incident Response, 72-Hour NGCB Notification, and Independent Investigation
  • NHPA-6 Reasonable Data Security and Breach Response
  • NGNDPR-5 Security of Personal Data, Breach Notification, and DPIA under NDPR Section 2.6-Security
  • NGOB-5 Fraud Monitoring, Incident Notification, and Reporting to CBN

OWASP MASVS · 1 control

  • OWASPMASVS-7 MASVS-RESILIENCE: Resilience Against Reverse Engineering

OWASP SAMM · 1 control

  • OWASPSAMM-5 Operations: Incident Management, Environment Management, Operational Management

OpenSSF Scorecard · 1 control

  • OSSFSC-8 Project Maintenance, Sustainability, Integration with Supply Chain Security
  • OREGONCPA-3 Consent, Sensitive Data, Children and Teen Protections
  • PASONE-6 Incident Management, Audit, Handover, Operational Phase, Decommissioning

PDPA Singapore · 1 control

  • PDPASG-8 Data Breach Notification, Incident Response, and Enforcement

PDPA Thailand · 1 control

  • PDPATH-8 Data Breach Notification, Complaints, Compliance, Enforcement

POPIA · 1 control

  • POPIASA-5 Security Safeguards, Encryption, Access Control, Operator Obligations

PTES · 1 control

  • PNGCYBER-4 Incident Response, Investigation, Evidence Preservation, Data Retention
  • NORWAY-8 Breach Notification, Complaints, Compliance, Enforcement

Privacy Act 2020 · 1 control

  • NZPRV-7 Notifiable Privacy Breach Scheme
  • SHAREASSESS-4 Vulnerability Management, Patching, Application Security

SLSA · 1 control

  • SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule
  • TSAPIPE-2 OT/IT Network Segmentation and Access Control

Taiwan PDPA · 1 control

Turkey KVKK · 1 control

Uruguay DPL · 1 control

Vietnam PDPD · 1 control

Virginia CDPA · 1 control

  • VPSHR-3 Implementation Guidance and Reporting

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in IEC 62443: Incident Response & Recovery

Query this from an agent

The graph holds this control, the 313 it maps to, and the evidence behind each claim, over MCP and REST.