NATO Cyber Defence Policy and NATO Computer Incident Response Capability (NCIRC)
Incident Response

NATO Cyber Defence Policy and NATO Computer Incident Response Capability (NCIRC) NATO-NCIRC-5: Incident Triage, Response, and Rapid Reaction Teams

Operate incident triage and categorisation per NATO incident severity matrix (Cat I to Cat V) aligned with NCIRC reporting taxonomy. Maintain capability to support NATO Rapid Reaction Teams (RRT) per the Cyber Defence Pledge - deployable cyber experts who can be activated within 48 hours to assist NATO nations under significant cyber attack. Coordinate with EU Cyber Diplomacy Toolbox + UN Group of Governmental Experts (GGE) + Open-Ended Working Group (OEWG) responsible state behaviour norms. Maintain incident logs for minimum 7 years.

Query this from an agent

The graph holds this control, the 7 it maps to, and the evidence behind each claim, over MCP and REST.