NIST SP 800-137
IR and Authorisation

NIST SP 800-137 7: Incident Response Integration and Ongoing Authorization

Integrate ISCM with Incident Response per Section 4.7 including: SIEM alerts feeding IR + threat hunting + playbook automation per SOAR (Cortex XSOAR + Splunk SOAR + Tines + Swimlane + Microsoft Sentinel Playbooks) + Continuous Adversary Emulation per MITRE Caldera or AttackIQ. Support Ongoing Authorization per Section 4.8 + NIST SP 800-37 RMF including event-driven authorisation reviews + system risk monitoring + control effectiveness assessment + authorisation decision support + Authorisation to Operate (ATO) reviews and Type Authorizations. Apply Asset Inventory Currency monitoring including HW + SW + Cloud + IoT + OT asset discovery + classification + ownership.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.