IEEE 1686
IEEE 1686 IR + Recovery + Reporting

IEEE 1686 IR-Recovery-Reporting-Exercises-Drills-RECOV: IEEE 1686 - Incident Response + Recovery from Failed Update + Reporting to Authorities + Coordination with Sector-Specific Agencies + Exercises and Drills

IR + Recovery elements per coordination with IEEE 1686 + sector-specific cybersecurity requirements. Incident response plan for operational disruptions per NERC CIP-008 + NIST SP 800-61 ICS adaptation: detection + classification (operational impact + safety + reliability) + containment + eradication + recovery + post-incident; response team + Cyber Security Incident Response Team (CSIRT) + Operations + Engineering coordination. IED Recovery from Failed Update (RECOV): backup configuration + restore + spare IED + transitional protection + remedial action scheme (RAS) + special protection schemes (SPS) availability + emergency manual operation; redundancy + N-1 + N-1-1 contingency. Reporting obligations to authorities: NERC EOP-004 (Event Reporting) + NERC CIP-008 (Cyber Security Incident Reporting and Response Planning) + Department of Energy DOE OE-417 (Electric Emergency Incident and Disturbance Report) + Cybersecurity and Infrastructure Security Agency CISA reporting + state public utility commission + sectoral CSIRT (Electricity Information Sharing and Analysis Center E-ISAC + ICS-ISAC + DOE-CESER); criminal referral (FBI Cyber + Secret Service); national CSIRT in non-US. Coordination with sector-specific agencies: NERC + Federal Energy Regulatory Commission FERC + DOE Cybersecurity Energy Security and Emergency Response (CESER) + CISA + E-ISAC; in non-US: ENISA + ENTSO-E + national grid operators + ENTSO-E Cybersecurity Maturity Model + IEEE Power System Relaying and Control Committee. Exercises and drills for OT incidents: tabletop + functional + capstone + GridEx (NERC Grid Exercise biennial) + Cyber Storm + DOE CRISP + utility-specific; lessons learned + improvement actions + sharing with E-ISAC. Coordinates with NIST SP 800-61 + NIST SP 800-82 + NERC CIP-008 + NERC CIP-009 (Recovery Plans for BES Cyber Systems) + DOE OE-417 + GridEx + DOE CRISP + E-ISAC.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.