Frameworks / NIST Cybersecurity Framework 2.0 / NIST-CSF-RS.AN-07 NIST Cybersecurity Framework 2.0
RS - Respond
NIST Cybersecurity Framework 2.0 NIST-CSF-RS.AN-07: Incident data and metadata are collected, and their integrity and provenance are preserved Incident data and metadata are collected, and their integrity and provenance are preserved
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 104 controls across 28 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
AC-2(4) Automated Audit Actions AU-3 Content of Audit Records AU-9 Protection of Audit Information AU-9(4) Access by Subset of Privileged Users IR-5 Incident Monitoring IR-7(1) Incident Response Assistance | Automation Support for Availability of Information and Support (IR-7(1)) SA-1 Policy and Procedures SA-2 Allocation of Resources SI-4(1) System Monitoring | System-wide Intrusion Detection System (SI-4(1)) SI-4(18) System Monitoring | Analyze Traffic and Covert Exfiltration (SI-4(18)) SI-4(2) Automated Tools and Mechanisms for Real-Time Analysis SI-7(7) Integration of Detection and Response AC-2(4) Automated Audit Actions AU-3 Content of Audit Records AU-9 Protection of Audit Information AU-9(4) Access by Subset of Privileged Users IR-5 Incident Monitoring IR-7(1) Incident Response Assistance | Automation Support for Availability of Information and Support (IR-7(1)) SA-1 Policy and Procedures SA-2 Allocation of Resources SI-4(1) System Monitoring | System-wide Intrusion Detection System (SI-4(1)) SI-4(18) System Monitoring | Analyze Traffic and Covert Exfiltration (SI-4(18)) SI-4(2) Automated Tools and Mechanisms for Real-Time Analysis SI-7(7) Integration of Detection and Response CIS-13.1 Centralize Security Event Alerting CIS-3.14 Log Sensitive Data Access CIS-8.1 Establish and Maintain an Audit Log Management Process CIS-8.10 Retain Audit Logs CIS-8.11 Conduct Audit Log Reviews CIS-8.5 Collect Detailed Audit Logs CIS-8.7 Collect URL Request Audit Logs CIS-8.9 Centralize Audit Logs 5.6 Operation 5.7.1 Monitoring, measurement, analysis and evaluation 6.13.1 Management of information security incidents and improvements 6.9.4 Logging and monitoring 6.9.7 Information systems audit considerations 7.2.8 Records related to processing PII 7.5.3 Records of transfer of PII SOC2-CC2.1 CC2.1 Relevant, quality information to support internal control (COSO principle 13) SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities SOC2-CC7.2 CC7.2 Monitoring system components for anomalies SOC2-CC7.3 CC7.3 Evaluating security events to identify incidents SOC2-CC7.4 CC7.4 Responding to security incidents SOC2-P6.2 P6.2 Record of authorised disclosures SOC2-P6.3 P6.3 Record of unauthorised disclosures and breaches 10.2.1 10.2.1 Audit logging enabled on all system components 10.2.2 10.2.2 Required details recorded for each auditable event 10.3.2 10.3.2 Audit log files protected from modification 10.3.3 10.3.3 Audit logs promptly backed up to central secure storage 10.3.4 10.3.4 File integrity monitoring on audit logs 5.28 Collection of evidence 5.33 Protection of records 5.7 Threat intelligence 8.15 Logging ISM-0138 Maintaining the integrity of evidence ISM-1815 Protecting event logs from modification and deletion ISM-1985 Protecting event logs from unauthorised access ASBv3-IR-7 Post-incident activity - conduct lesson learned and retain evidence LT-3 Enable logging for security investigation C5-OPS-12 Logging and Monitoring - Access, Storage and Deletion C5-OPS-14 Logging and Monitoring - Storage of the Logging Data 5.28 Collection of evidence 5.33 Protection of records ASD37-33 Capture network traffic (Limited) GDPR-Art.33 Notification of a personal data breach to the supervisory authority 9.1 Monitoring, measurement, analysis and evaluation 7.5.3 Control of documented information Art.23.4.b Submit an incident notification within 72 hours, with an initial assessment and indicators of compromise RS.AN-07 RS.AN-07 Incident data collected and retained as evidence under preservation procedures SEC-CYB-18 Historical Incident Tracking and Repeat Disclosure Analysis Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in RS - Respond You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done? NIST Cybersecurity Framework 2.0 NIST-CSF-RS.AN-07 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.
Query this from an agent The graph holds this control, the 104 it maps to, and the evidence behind each claim, over MCP and REST.