Frameworks / MARS-E / MARS-E-Incident-Response-Breach-Notification-IR-Family-45-CFR-164-400-414-IRS-Pub-1075-Notification-CMS-IRT MARS-E
Incident Response and Breach Notification - MARS-E v2.0
MARS-E MARS-E-Incident-Response-Breach-Notification-IR-Family-45-CFR-164-400-414-IRS-Pub-1075-Notification-CMS-IRT: MARS-E Incident Response + Breach Notification + IR Family + 45 CFR 164.400-414 + IRS Pub 1075 + CMS IRT Implement NIST 800-53 IR Incident Response family + breach notification process integrated across HIPAA + ACA + IRS Pub 1075. Incident response capability with 24x7 SOC + Computer Security Incident Response Team (CSIRT) + incident response plan + tabletop and live exercises annually. Categorisation per US-CERT incident categories + CMS Incident Response Team (IRT) coordination + DHS/CISA reporting for major incidents. HIPAA Breach Notification Rule 45 CFR 164.400-414 (60 days to affected individuals + 60 days to HHS + media notification if 500+ residents in state). Risk Assessment (Acquisition + Unauthorised Access + Disposition + Identification) for PHI breaches per HHS guidance. ACA Section 1411 breach notification to CMS + affected consumers. IRS Pub 1075 Section 10 incident reporting (within 1 hour for known + 24 hours for suspected disclosure of FTI). State breach notification law coordination (47 states + DC). CMS-issued Incident Reporting Procedure + Authorization Protocol. Post-incident review + root cause analysis + lessons learned + control updates. Annual incident response capability assessment.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 138 controls across 52 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
ISO27043-11 Access control policy and enforcement ISO27043-14 Privileged access management ISO27043-15 Access review and recertification ISO27043-17 Encryption of data at rest ISO27043-18 Encryption of data in transit ISO27043-19 Certificate management ISO27043-20 Key lifecycle management ISO21434-12 User access management and provisioning ISO21434-14 Privileged access management ISO21434-15 Access review and recertification ISO21434-16 Cryptographic policy and key management ISO21434-17 Encryption of data at rest ISO21434-18 Encryption of data in transit ISO21434-19 Certificate management ISO27799-01 ePHI access controls and authorization ISO27799-02 ePHI encryption at rest and in transit ISO27799-08 Information access management ISO27799-16 Transmission security and encryption ISO27799-17 Facility access controls AWWA-2.1 User Access Management AWWA-2.4 Physical Access Controls AWWA-3.2 Remote Access Security AWWA-3.4 Encryption and Data Protection BSI-03 Multi-factor authentication requirements BSI-04 Remote access controls BSI-05 Wireless access restrictions BSI-08 Cryptographic protection of data PQC-2 FIPS 203 ML-KEM Implementation - Module-Lattice Key-Encapsulation Mechanism PQC-5 Cryptographic Inventory and PQC Migration Roadmap PQC-7 FIPS Validated Modules, HSM Readiness, and Algorithm Validation PQC-8 Implementation Requirements - RNG, Side-Channel, Key Management, Operations, Incident Response API1164-06 Access Control API1164-07 Remote Access API1164-09 Patch and Vulnerability Management FEDRAMP-SC-13 Cryptographic Protection FEDRAMP-SC-28 Protection of Information at Rest FEDRAMP-SC-8 Transmission Confidentiality and Integrity IEC62443-07 Personnel risk assessment IEC62443-08 Electronic access perimeter management IEC62443-10 Revocation of access procedures 23837-1.2 Normative references 23837-1.5.2 Cryptographic module requirements 23837-1.5.3 Network device testing requirements 27010-10.1 Cryptographic Protection 27010-9.1 Access Control to Shared Information 27010-9.2 Authentication of Sources 27011-5.3 Segregation of duties 27011-8.1 User Endpoint Devices 27011-8.3 Cryptography and key management ISO27019-07 Personnel risk assessment ISO27019-08 Electronic access perimeter management ISO27019-10 Revocation of access procedures OWASPTOP10-1 A01:2025 Broken Access Control OWASPTOP10-2 A02:2025 Cryptographic Failures and Secret Management OWASPTOP10-4 A04:2025 Insecure Design and Business Logic (incl. A11 API Abuse) ISMSP-AC-01 Access Control Policy ISMSP-AC-04 Network Access Control ISMSP-SYS-02 Encryption Implementation APPI-A26 Report of Leakage to the Commission and Notification to the Person APPI-A34 Request for Correction, Addition or Deletion DSO-2 Data Security DSO-3 Data Access Management CJIS-8 Media Protection CJIS-9 System and Communications Protection CAT-D3-1 Preventative controls CAT-D4-3 Third-party access controls UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5) UAE-PDPL-Art.6_7 Sensitive personal data and children's data (UAE PDPL Articles 6-7) 62351-8 Role-based access control (RBAC) 62351-9 Cyber security key management MY-PDPA-Cross-Border-Transfer-Section-129-Whitelist-Abolition-2024-Adequacy-SCC-BCR-Processor-Direct-Marketing Malaysia PDPA Cross-Border + Section 129 + Whitelist Abolition 2024 + Adequacy + SCC + BCR + Processor + Marketing MY-PDPA-Sensitive-Personal-Data-Section-40-Health-Religious-Political-Sexual-Children-Explicit-Consent Malaysia PDPA Sensitive Personal Data + Section 40 + Health + Religious + Political + Children + Explicit Consent OWASPAPI-1 Broken Object Level Authorization (BOLA) and BFLA OWASPAPI-6 Security Misconfiguration and Secure API Design PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight PSPF24-4 Physical Security IM8-CLD.2 Cloud Security Controls IM8-SEC.2 Access Control ASD37-17 TLS encryption between email servers (Limited) CA-ITSG33-SC-01 Security Control Catalogue FFIEC-09 Encryption and key management FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) IATA-IOSA-Section8-SEC-SecurityManagement-AVSEC IATA IOSA Section 8 - SEC Security Management + Aviation Security Programme (AVSEC) + ICAO Annex 17 Alignment ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18) ISO28001-PS-01 Facility Security ISO20000-15 Access management for services 27400-6.2 Device Identity and Authentication 29115-7.4 Level of Assurance 4 (LoA4) ITIL4-15 Access management for services NISTSP34-3 Preventive Controls and Recovery Strategies: Backup, Alternate Sites, Equipment DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management AUPRV-4 APP 10-11 Quality, Security of Personal Information PIPA-Cross-Border-Transfer-Articles-28-8-28-9-Adequacy-Standard-Contract-Certification-EU Korea PIPA Cross-Border Transfer + Articles 28-8 + 28-9 + Adequacy + EU 2021 TURKEYKVKK-2 Information Notice and Data Subject Rights CPSC-CS.2 Authentication and Access Controls USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR) Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Query this from an agent The graph holds this control, the 138 it maps to, and the evidence behind each claim, over MCP and REST.