Frameworks / NIST Cybersecurity Framework 2.0 / NIST-CSF-RS.CO-02 NIST Cybersecurity Framework 2.0
RS - Respond
NIST Cybersecurity Framework 2.0 NIST-CSF-RS.CO-02: Internal and external stakeholders are notified of incidents Internal and external stakeholders are notified of incidents. Control from NIST Cybersecurity Framework 2.0 framework, domain: RS - Respond.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 114 controls across 45 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
AC-2(4) Automated Audit Actions AU-5 Response to Audit Logging Process Failures AU-6 Audit Record Review, Analysis, and Reporting IR-6 Incident Reporting IR-6(1) Automated Reporting IR-6(3) Incident Reporting | Supply Chain Coordination (IR-6(3)) IR-7 Incident Response Assistance IR-7(1) Incident Response Assistance | Automation Support for Availability of Information and Support (IR-7(1)) IR-9 Information Spillage Response (IR-9) IR-9(4) Information Spillage Response | Exposure to Unauthorized Personnel (IR-9(4)) PE-13(2) Fire Protection | Suppression Systems: Automatic Activation and Notification (PE-13(2)) SR-8 Notification Agreements (SR-8) AC-2(4) Automated Audit Actions AU-5 Response to Audit Logging Process Failures AU-6 Audit Record Review, Analysis, and Reporting IR-6 Incident Reporting IR-6(1) Automated Reporting IR-6(3) Incident Reporting | Supply Chain Coordination (IR-6(3)) IR-7 Incident Response Assistance IR-7(1) Incident Response Assistance | Automation Support for Availability of Information and Support (IR-7(1)) IR-9 Information Spillage Response (IR-9) IR-9(4) Information Spillage Response | Exposure to Unauthorized Personnel (IR-9(4)) PE-13(2) Fire Protection | Suppression Systems: Automatic Activation and Notification (PE-13(2)) SR-8 Notification Agreements (SR-8) SOC2-CC2.2 CC2.2 Internal communication of objectives and control responsibilities (COSO principle 14) SOC2-CC2.3 CC2.3 Communication with external parties about internal control (COSO principle 15) SOC2-CC4.2 CC4.2 Evaluating and communicating control deficiencies (COSO principle 17) SOC2-P6.5 P6.5 Vendor commitments to report unauthorised disclosures SOC2-P6.6 P6.6 Notifying breaches and incidents SOC2-P8.1 P8.1 Inquiries, complaints, disputes and compliance monitoring CIS-17.2 Establish and Maintain Contact Information for Reporting Security Incidents CIS-17.3 Establish and Maintain an Enterprise Process for Reporting Incidents CIS-17.4 Establish and Maintain an Incident Response Process CIS-17.6 Define Mechanisms for Communicating During Incident Response Art. 14(3) Notifying severe incidents affecting product security Art. 14(4)(a) Early warning of a severe incident within 24 hours Art. 14(4)(b) Incident notification within 72 hours Art. 14(4)(c) Final incident report within one month of the notification 5.24 Information security incident management planning and preparation 5.26 Response to information security incidents 5.5 Contact with authorities 6.8 Information security event reporting 6.13 Information security incident management 6.13.1 Management of information security incidents and improvements 7.5 PII sharing, transfer, and disclosure 8.5.4 Notification of PII disclosure requests ISM-0123 Reporting incidents to the CISO ISM-0140 Reporting incidents to ASD ISM-1880 Reporting incidents involving customer data 7.4 Communication 8.4.2 Response structure 8.4.3 Warning and communication 5.26 Response to information security incidents 5.5 Contact with authorities 6.8 Information security event reporting A.8 Information for interested parties of AI systems A.8.3 External reporting A.8.4 Communication of incidents SEC-CYB-02 Form 8-K Item 1.05 Filing within Four Business Days SEC-CYB-11 Foreign Private Issuer Disclosures on Form 6-K and 20-F SECCYB-1 Material Cybersecurity Incident 4-Business-Day Disclosure (Item 1.05) CPS230-P33 APRA Notification of Operational Risk Incidents within 72 Hours CPS230-P42 APRA Notification of Disruption Outside Tolerance within 24 Hours CPS234-35 APRA Notification of Material Incidents within 72 Hours CPS234-P25 Response Plan Content and Escalation Mechanisms C5-OPS-21 Involvement of Cloud Customers in the Event of Incidents C5-SIM-03 Documentation and reporting of security incidents Art.23.1 Notify significant incidents to the CSIRT or competent authority, and warn affected service recipients Art.23.4.a Submit an early warning within 24 hours of becoming aware of a significant incident E8-APP-ML3 Application Control (ML3) ANSSI-HYG-40 Define a Security Incident Management Procedure APPI-A26 Report of Leakage to the Commission and Notification to the Person SEC10-BP01 Identify key personnel and external resources AESCSF-IR-4 Incident reporting SAFE-AEO-D Consultation, Co-operation and Communication ASBv3-IR-2 Preparation - setup incident notification BE-CF-20 Incident reporting and notification BMA-15 Notification of Cyber Reporting Events to the Authority DFARS-7012-c Cyber incident reporting (72-hour rapid report) GDPR-Art.33 Notification of a personal data breach to the supervisory authority RS.CO-2 RS.CO-2: Events are reported consistent with established criteria RS.CO-2 RS.CO-2: Incidents are reported consistent with established criteria 03.06.02 Incident Monitoring, Reporting, and Response Assistance RS.CO-02 RS.CO-02 Stakeholders, affected parties, regulators and law enforcement notified as required 12.10.1 12.10.1 Incident response plan ready for activation Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in RS - Respond You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done? NIST Cybersecurity Framework 2.0 NIST-CSF-RS.CO-02 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.
Query this from an agent The graph holds this control, the 114 it maps to, and the evidence behind each claim, over MCP and REST.