NIST Cybersecurity Framework 2.0
RS - Respond

NIST Cybersecurity Framework 2.0 NIST-CSF-RS.CO-02: Internal and external stakeholders are notified of incidents

Internal and external stakeholders are notified of incidents. Control from NIST Cybersecurity Framework 2.0 framework, domain: RS - Respond.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 114 controls across 45 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

FedRAMP High · 12 controls

  • AC-2(4) Automated Audit Actions
  • AU-5 Response to Audit Logging Process Failures
  • AU-6 Audit Record Review, Analysis, and Reporting
  • IR-6 Incident Reporting
  • IR-6(1) Automated Reporting
  • IR-6(3) Incident Reporting | Supply Chain Coordination (IR-6(3))
  • IR-7 Incident Response Assistance
  • IR-7(1) Incident Response Assistance | Automation Support for Availability of Information and Support (IR-7(1))
  • IR-9 Information Spillage Response (IR-9)
  • IR-9(4) Information Spillage Response | Exposure to Unauthorized Personnel (IR-9(4))
  • PE-13(2) Fire Protection | Suppression Systems: Automatic Activation and Notification (PE-13(2))
  • SR-8 Notification Agreements (SR-8)

FedRAMP Moderate · 12 controls

  • AC-2(4) Automated Audit Actions
  • AU-5 Response to Audit Logging Process Failures
  • AU-6 Audit Record Review, Analysis, and Reporting
  • IR-6 Incident Reporting
  • IR-6(1) Automated Reporting
  • IR-6(3) Incident Reporting | Supply Chain Coordination (IR-6(3))
  • IR-7 Incident Response Assistance
  • IR-7(1) Incident Response Assistance | Automation Support for Availability of Information and Support (IR-7(1))
  • IR-9 Information Spillage Response (IR-9)
  • IR-9(4) Information Spillage Response | Exposure to Unauthorized Personnel (IR-9(4))
  • PE-13(2) Fire Protection | Suppression Systems: Automatic Activation and Notification (PE-13(2))
  • SR-8 Notification Agreements (SR-8)

SOC 2 · 6 controls

  • SOC2-CC2.2 CC2.2 Internal communication of objectives and control responsibilities (COSO principle 14)
  • SOC2-CC2.3 CC2.3 Communication with external parties about internal control (COSO principle 15)
  • SOC2-CC4.2 CC4.2 Evaluating and communicating control deficiencies (COSO principle 17)
  • SOC2-P6.5 P6.5 Vendor commitments to report unauthorised disclosures
  • SOC2-P6.6 P6.6 Notifying breaches and incidents
  • SOC2-P8.1 P8.1 Inquiries, complaints, disputes and compliance monitoring

CIS Controls v8 · 4 controls

  • CIS-17.2 Establish and Maintain Contact Information for Reporting Security Incidents
  • CIS-17.3 Establish and Maintain an Enterprise Process for Reporting Incidents
  • CIS-17.4 Establish and Maintain an Incident Response Process
  • CIS-17.6 Define Mechanisms for Communicating During Incident Response
  • Art. 14(3) Notifying severe incidents affecting product security
  • Art. 14(4)(a) Early warning of a severe incident within 24 hours
  • Art. 14(4)(b) Incident notification within 72 hours
  • Art. 14(4)(c) Final incident report within one month of the notification

HIPAA Security Rule · 4 controls

ISO 27001:2022 · 4 controls

  • 5.24 Information security incident management planning and preparation 
  • 5.26 Response to information security incidents
  • 5.5 Contact with authorities
  • 6.8 Information security event reporting

ISO 27701:2019 · 4 controls

  • 6.13 Information security incident management
  • 6.13.1 Management of information security incidents and improvements
  • 7.5 PII sharing, transfer, and disclosure
  • 8.5.4 Notification of PII disclosure requests

NIST SP 800-53 Rev 5 · 4 controls

  • ISM-0123 Reporting incidents to the CISO
  • ISM-0140 Reporting incidents to ASD
  • ISM-1880 Reporting incidents involving customer data

CMMC 2.0 · 3 controls

ISO 22301:2019 · 3 controls

  • 7.4 Communication
  • 8.4.2 Response structure
  • 8.4.3 Warning and communication

ISO 27002:2022 · 3 controls

  • 5.26 Response to information security incidents
  • 5.5 Contact with authorities
  • 6.8 Information security event reporting

ISO/IEC 42001:2023 · 3 controls

  • A.8 Information for interested parties of AI systems
  • A.8.3 External reporting
  • A.8.4 Communication of incidents
  • SEC-CYB-02 Form 8-K Item 1.05 Filing within Four Business Days
  • SEC-CYB-11 Foreign Private Issuer Disclosures on Form 6-K and 20-F
  • SECCYB-1 Material Cybersecurity Incident 4-Business-Day Disclosure (Item 1.05)
  • CPS230-P33 APRA Notification of Operational Risk Incidents within 72 Hours
  • CPS230-P42 APRA Notification of Disruption Outside Tolerance within 24 Hours

APRA CPS 234 · 2 controls

  • CPS234-35 APRA Notification of Material Incidents within 72 Hours
  • CPS234-P25 Response Plan Content and Escalation Mechanisms

C5 (Germany) · 2 controls

  • C5-OPS-21 Involvement of Cloud Customers in the Event of Incidents
  • C5-SIM-03 Documentation and reporting of security incidents

DORA · 2 controls

NIS2 Directive · 2 controls

  • Art.23.1 Notify significant incidents to the CSIRT or competent authority, and warn affected service recipients
  • Art.23.4.a Submit an early warning within 24 hours of becoming aware of a significant incident

NIST SP 800-161 Rev 1 · 2 controls

NIST SP 800-66 Rev 2 · 2 controls

  • E8-APP-ML3 Application Control (ML3)
  • ANSSI-HYG-40 Define a Security Incident Management Procedure

APPI · 1 control

  • APPI-A26 Report of Leakage to the Commission and Notification to the Person
  • SEC10-BP01 Identify key personnel and external resources
  • AESCSF-IR-4 Incident reporting
  • SAFE-AEO-D Consultation, Co-operation and Communication
  • ASBv3-IR-2 Preparation - setup incident notification
  • BE-CF-20 Incident reporting and notification
  • BMA-15 Notification of Cyber Reporting Events to the Authority
  • DFARS-7012-c Cyber incident reporting (72-hour rapid report)

GDPR · 1 control

  • GDPR-Art.33 Notification of a personal data breach to the supervisory authority
  • RS.CO-2 RS.CO-2: Events are reported consistent with established criteria
  • RS.CO-2 RS.CO-2: Incidents are reported consistent with established criteria
  • 03.06.02 Incident Monitoring, Reporting, and Response Assistance

NIST SP 800-218 · 1 control

  • RS.CO-02 RS.CO-02 Stakeholders, affected parties, regulators and law enforcement notified as required

PCI DSS 4.0 · 1 control

  • 12.10.1 12.10.1 Incident response plan ready for activation

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in RS - Respond

You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done?

NIST Cybersecurity Framework 2.0 NIST-CSF-RS.CO-02 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 114 it maps to, and the evidence behind each claim, over MCP and REST.