NIST SP 1800-32
NIST SP 1800-32: Incident Response & Recovery

NIST SP 1800-32 32-20: Exercises and drills for OT incidents

Exercises and drills for OT incidents. Control from NIST SP 1800-32 framework, domain: NIST SP 1800-32: Incident Response & Recovery.

What else in your programme already covers this

This control maps to 255 controls across 106 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • ASD37-31 Hunt to discover incidents (Very Good)
  • ASD37-33 Capture network traffic (Limited)
  • ASD37-34 Regular backups (Essential)
  • ASD37-35 Business continuity and disaster recovery plans (Very Good)
  • ASD37-36 System recovery capabilities (Very Good)
  • NIST-CSF-ID.IM-04 Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved
  • NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process
  • NIST-CSF-RC.RP-06 The end of incident recovery is declared based on criteria, and incident-related documentation is completed
  • NIST-CSF-RS.MA-01 The incident response plan is executed in coordination with relevant third parties once an incident is declared
  • NIST-CSF-RS.MA-05 The criteria for initiating incident recovery are applied

NIST SP 800-53 Rev 5 · 5 controls

  • FFIEC-12 Disaster recovery procedures
  • FFIEC-23 Regulatory reporting requirements
  • FFIEC-24 Customer notification procedures
  • FFIEC-25 Post-incident review and improvement

PCI P2PE · 4 controls

PCI PIN Security · 4 controls

PCI SSF · 4 controls

SOC 2 · 4 controls

  • SOC2-A1.2 Environmental protections, data backups, and recovery infrastructure support availability
  • SOC2-A1.3 Recovery plan procedures support system recovery from failures
  • SOC2-CC7.4 Responds to identified security incidents through defined procedures
  • SOC2-CC7.5 Identifies the root cause of security incidents

API 1164 · 3 controls

BSI IT-Grundschutz · 3 controls

  • BSI-18 Incident response planning and testing
  • BSI-20 Incident reporting and notification
  • BSI-21 Forensic analysis capabilities

IEC 62443 · 3 controls

ISO 22320:2018 · 3 controls

ISO 27019 · 3 controls

ISO/IEC 27031:2011 · 3 controls

  • 3.6 Encrypt Data on End-User Devices
  • 3.6.1 Procedures are defined and implemented to protect cryptographic keys used to protect stored account data against disclosure and misuse that include: • Access to keys is restricted to the fewest number of custodians necessary.
  • FEDRAMP-CP-9 System Backup

OSFI B-13 · 3 controls

  • OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery
  • OSFIB13-7 Incident Reporting to OSFI and Regulatory Coordination
  • OSFIB13-8 Metrics, Monitoring, Continuous Improvement, Maturity

PSD2 SCA · 3 controls

  • PSDTWO-2 SCA Exemptions and Risk-Based Authentication
  • PSDTWO-3 Common and Secure Communication, API Access for AISPs and PISPs
  • PSDTWO-4 Fraud Reporting and Incident Management

South Korea ISMS-P · 3 controls

  • D.1 Incident Response Planning
  • D.2 Incident Reporting
  • D.3 Backup and Recovery

APPI · 2 controls

  • APPI-A41 Preparation and Handling of Pseudonymized Personal Information
  • APPI-A43 Preparation of Anonymized Personal Information

APRA CPS 234 · 2 controls

  • CPS234-21 Implementation of Information Security Controls
  • CPS234-25 Internal Audit Review of Information Security Controls
  • 4.4.7 Emergency and Incident Response
  • 4.4.8 Business Continuity and Recovery

Bahrain PDPL · 2 controls

ISO 22316 · 2 controls

ISO 22317 · 2 controls

ISO 22318 · 2 controls

ISO 27017 · 2 controls

ISO 27018 · 2 controls

ISO/IEC 30111:2019 · 2 controls

NIST SP 800-190 · 2 controls

  • NJDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • NJDPA-6 Reasonable Data Security and Incident Response
  • OMANCS-6 Security Monitoring, Detection, Incident Response, and OmanCERT Notification
  • OMANCS-7 Business Continuity, Disaster Recovery, and Resilience

Open Banking Security · 2 controls

  • OPENBANK-7 Logging, Monitoring, Regulatory Reporting, SLA, Availability
  • OPENBANK-8 Incident Detection, Response, Customer Notification, Post-Incident Review, BCM

Peru DPL · 2 controls

  • PERU-7 DPO, Records, Retention, Marketing, Training
  • PERU-8 Breach Notification, ANPD Cooperation, Sanctions, Compliance

Qatar DPL · 2 controls

  • QATAR-5 Security of Processing
  • QATAR-8 Breach Notification, Compliance, Enforcement

Saudi Arabia PDPL · 2 controls

South Korea PIPA · 2 controls

  • PMF-M.4 Privacy Incident Management
  • CPS230-13 Board Accountability for Operational Risk Management
  • BB-DPA-20 Sections 50-60 - Registration and Responsibilities
  • CA-12 Deploys Through Policies and Procedures
  • DIQ-1 Data Integration and Interoperability

ISO 20000-1 · 1 control

ISO 27043 · 1 control

ISO/IEC 27010:2015 · 1 control

ISO/IEC 27011:2024 · 1 control

ISO/IEC 27400:2022 · 1 control

  • 27400-6.5 Security monitoring and incident response

ISO/IEC 29147:2018 · 1 control

ISO/SAE 21434 · 1 control

ITIL 4 · 1 control

  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)

NIST SP 800-171 · 1 control

  • 3.6.1 Procedures are defined and implemented to protect cryptographic keys used to protect stored account data against disclosure and misuse that include: • Access to keys is restricted to the fewest number of custodians necessary.

NIST SP 800-61 · 1 control

NIST SP 800-63-4 · 1 control

  • NISTSP63R4-4 Authenticator Lifecycle: Binding, Recovery, Replacement, Suspension, Revocation
  • NISTSP82-7 OT Incident Response, Forensics, Recovery, and Continuity

NIST SP 800-88 · 1 control

  • NISTSP88-5 Media Inventory, Tracking, Chain of Custody, and Sanitization Records

NIST SP 800-92 · 1 control

  • NISTSP92-6 Log Retention: Policy, Tiered Storage, Backup, Secure Disposal, Legal Hold
  • NRFCS-7 Detection, Logging, Incident Response, Breach Notification, and Fraud Detection
  • NGCB-6 Incident Response, 72-Hour NGCB Notification, and Independent Investigation
  • NGOB-5 Fraud Monitoring, Incident Notification, and Reporting to CBN

OWASP SAMM · 1 control

  • OWASPSAMM-5 Operations: Incident Management, Environment Management, Operational Management

OpenSSF Scorecard · 1 control

  • OSSFSC-8 Project Maintenance, Sustainability, Integration with Supply Chain Security
  • OREGONCPA-3 Consent, Sensitive Data, Children and Teen Protections
  • PASONE-6 Incident Management, Audit, Handover, Operational Phase, Decommissioning

PDPA Singapore · 1 control

  • PDPASG-8 Data Breach Notification, Incident Response, and Enforcement

PDPA Thailand · 1 control

  • PDPATH-8 Data Breach Notification, Complaints, Compliance, Enforcement

POPIA · 1 control

  • POPIASA-5 Security Safeguards, Encryption, Access Control, Operator Obligations

PTES · 1 control

  • PNGCYBER-4 Incident Response, Investigation, Evidence Preservation, Data Retention
  • NORWAY-8 Breach Notification, Complaints, Compliance, Enforcement

Privacy Act 2020 · 1 control

  • NZPRV-7 Notifiable Privacy Breach Scheme
  • SHAREASSESS-4 Vulnerability Management, Patching, Application Security

SLSA · 1 control

  • SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule
  • TSAPIPE-2 OT/IT Network Segmentation and Access Control

Taiwan PDPA · 1 control

Uruguay DPL · 1 control

Vietnam PDPD · 1 control

Virginia CDPA · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in NIST SP 1800-32: Incident Response & Recovery

Query this from an agent

The graph holds this control, the 255 it maps to, and the evidence behind each claim, over MCP and REST.