Frameworks / NIST SP 800-171 Rev 3 / 03.06.01 NIST SP 800-171 Rev 3
03.06 IR (Incident Response)
NIST SP 800-171 Rev 3 03.06.01: Incident Handling Implement incident handling capability including preparation, detection and analysis, containment, eradication, recovery, and post-incident activity.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 72 controls across 27 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-DE.AE-02 Potentially adverse events are analyzed to better understand associated activities NIST-CSF-DE.AE-04 The estimated impact and scope of adverse events are understood NIST-CSF-DE.AE-08 Incidents are declared when adverse events meet the defined incident criteria NIST-CSF-ID.IM-03 Improvements are identified from execution of operational processes, procedures, and activities NIST-CSF-ID.IM-04 Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved NIST-CSF-RS.AN-03 Analysis is performed to establish what has taken place during an incident and the root cause of the incident NIST-CSF-RS.AN-08 An incident's magnitude is estimated and validated NIST-CSF-RS.MA-03 Incidents are categorized and prioritized NIST-CSF-RS.MA-05 The criteria for initiating incident recovery are applied NIST-CSF-RS.MI-01 Incidents are contained NIST-CSF-RS.MI-02 Incidents are eradicated ASBv3-IR-1 Preparation - update incident response plan and handling process ASBv3-IR-4 Detection and analysis - investigate an incident ASBv3-IR-5 Detection and analysis - prioritize incidents ASBv3-IR-6 Containment, eradication and recovery - automate the incident handling ASBv3-IR-7 Post-incident activity - conduct lesson learned and retain evidence 5.24 Information security incident management planning and preparation 5.25 Assessment and decision on information security events 5.26 Response to information security incidents 5.27 Learning from information security incidents 5.24 Information security incident management planning and preparation 5.25 Assessment and decision on information security events 5.26 Response to information security incidents 5.27 Learning from information security incidents 10.4.3 10.4.3 Exceptions and anomalies from log review addressed 10.7.3 10.7.3 Respond promptly to critical security control failures 12.10.1 12.10.1 Incident response plan ready for activation 12.10.5 12.10.5 Plan covers alerts from security monitoring systems CIS-17.4 Establish and Maintain an Incident Response Process CIS-17.8 Conduct Post-Incident Reviews CIS-17.9 Establish and Maintain Security Incident Thresholds SOC2-CC7.3 CC7.3 Evaluating security events to identify incidents SOC2-CC7.4 CC7.4 Responding to security incidents SOC2-CC7.5 CC7.5 Recovering from security incidents CPS234-30 Detection and Response Mechanisms CPS234-P25 Response Plan Content and Escalation Mechanisms ASD37-28 Continuous incident detection and response (Excellent) ASD37-30 Endpoint detection and response (Very Good) IR-4 Incident Handling IR-4(1) Automated Incident Handling Processes IR-4 Incident Handling IR-4(1) Automated Incident Handling Processes 3.6.1e Establish Security Operations Center (SOC) 3.6.2e Establish and Maintain a Cyber Incident Response Team E8-APP-ML2 Application Control (ML2) ANSSI-HYG-40 Define a Security Incident Management Procedure CPS230-27 Identification and Escalation of Incidents and Near Misses CFTC-SS-16 Security Incident Response Plan and Testing 6.13.1 Management of information security incidents and improvements Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in 03.06 IR (Incident Response) You are reading one control. How much of NIST SP 800-171 Rev 3 have you already done? NIST SP 800-171 Rev 3 03.06.01 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST SP 800-171 Rev 3 your existing evidence covers. Hold PCI DSS 4.0 and 69 of 97 NIST SP 800-171 Rev 3 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the PCI DSS 4.0 pair alone.
Query this from an agent The graph holds this control, the 72 it maps to, and the evidence behind each claim, over MCP and REST.