NIST SP 800-171 Rev 3
03.06 IR (Incident Response)

NIST SP 800-171 Rev 3 03.06.01: Incident Handling

Implement incident handling capability including preparation, detection and analysis, containment, eradication, recovery, and post-incident activity.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 72 controls across 27 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-DE.AE-02 Potentially adverse events are analyzed to better understand associated activities
  • NIST-CSF-DE.AE-04 The estimated impact and scope of adverse events are understood
  • NIST-CSF-DE.AE-08 Incidents are declared when adverse events meet the defined incident criteria
  • NIST-CSF-ID.IM-03 Improvements are identified from execution of operational processes, procedures, and activities
  • NIST-CSF-ID.IM-04 Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved
  • NIST-CSF-RS.AN-03 Analysis is performed to establish what has taken place during an incident and the root cause of the incident
  • NIST-CSF-RS.AN-08 An incident's magnitude is estimated and validated
  • NIST-CSF-RS.MA-03 Incidents are categorized and prioritized
  • NIST-CSF-RS.MA-05 The criteria for initiating incident recovery are applied
  • NIST-CSF-RS.MI-01 Incidents are contained
  • NIST-CSF-RS.MI-02 Incidents are eradicated
  • ASBv3-IR-1 Preparation - update incident response plan and handling process
  • ASBv3-IR-4 Detection and analysis - investigate an incident
  • ASBv3-IR-5 Detection and analysis - prioritize incidents
  • ASBv3-IR-6 Containment, eradication and recovery - automate the incident handling
  • ASBv3-IR-7 Post-incident activity - conduct lesson learned and retain evidence

ISO 27001:2022 · 4 controls

  • 5.24 Information security incident management planning and preparation 
  • 5.25 Assessment and decision on information security events
  • 5.26 Response to information security incidents
  • 5.27 Learning from information security incidents

ISO 27002:2022 · 4 controls

  • 5.24 Information security incident management planning and preparation
  • 5.25 Assessment and decision on information security events
  • 5.26 Response to information security incidents
  • 5.27 Learning from information security incidents

PCI DSS 4.0 · 4 controls

  • 10.4.3 10.4.3 Exceptions and anomalies from log review addressed
  • 10.7.3 10.7.3 Respond promptly to critical security control failures
  • 12.10.1 12.10.1 Incident response plan ready for activation
  • 12.10.5 12.10.5 Plan covers alerts from security monitoring systems

C5 (Germany) · 3 controls

CIS Controls v8 · 3 controls

  • CIS-17.4 Establish and Maintain an Incident Response Process
  • CIS-17.8 Conduct Post-Incident Reviews
  • CIS-17.9 Establish and Maintain Security Incident Thresholds

HIPAA Security Rule · 3 controls

NIST SP 800-66 Rev 2 · 3 controls

SOC 2 · 3 controls

  • SOC2-CC7.3 CC7.3 Evaluating security events to identify incidents
  • SOC2-CC7.4 CC7.4 Responding to security incidents
  • SOC2-CC7.5 CC7.5 Recovering from security incidents

APRA CPS 234 · 2 controls

  • CPS234-30 Detection and Response Mechanisms
  • CPS234-P25 Response Plan Content and Escalation Mechanisms
  • ASD37-28 Continuous incident detection and response (Excellent)
  • ASD37-30 Endpoint detection and response (Very Good)

FedRAMP High · 2 controls

  • IR-4 Incident Handling
  • IR-4(1) Automated Incident Handling Processes

FedRAMP Moderate · 2 controls

  • IR-4 Incident Handling
  • IR-4(1) Automated Incident Handling Processes

NIST SP 800-161 Rev 1 · 2 controls

NIST SP 800-172 · 2 controls

  • 3.6.1e Establish Security Operations Center (SOC)
  • 3.6.2e Establish and Maintain a Cyber Incident Response Team
  • E8-APP-ML2 Application Control (ML2)
  • ANSSI-HYG-40 Define a Security Incident Management Procedure
  • CPS230-27 Identification and Escalation of Incidents and Near Misses
  • CFTC-SS-16 Security Incident Response Plan and Testing

CMMC 2.0 · 1 control

ISO 27701:2019 · 1 control

  • 6.13.1 Management of information security incidents and improvements

NIS2 Directive · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in 03.06 IR (Incident Response)

You are reading one control. How much of NIST SP 800-171 Rev 3 have you already done?

NIST SP 800-171 Rev 3 03.06.01 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST SP 800-171 Rev 3 your existing evidence covers. Hold PCI DSS 4.0 and 69 of 97 NIST SP 800-171 Rev 3 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the PCI DSS 4.0 pair alone.

Query this from an agent

The graph holds this control, the 72 it maps to, and the evidence behind each claim, over MCP and REST.