NIST SP 800-171 Rev 3
03.06 IR (Incident Response)

NIST SP 800-171 Rev 3 03.06.02: Incident Monitoring, Reporting, and Response Assistance

Track and document incidents; report incidents to designated personnel and authorities within required timeframes; provide incident response assistance.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 63 controls across 26 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27001:2022 · 5 controls

  • 5.25 Assessment and decision on information security events
  • 5.26 Response to information security incidents
  • 5.28 Collection of evidence
  • 5.5 Contact with authorities
  • 6.8 Information security event reporting

SOC 2 · 5 controls

  • SOC2-CC2.3 CC2.3 Communication with external parties about internal control (COSO principle 15)
  • SOC2-CC7.3 CC7.3 Evaluating security events to identify incidents
  • SOC2-CC7.4 CC7.4 Responding to security incidents
  • SOC2-P6.3 P6.3 Record of unauthorised disclosures and breaches
  • SOC2-P6.6 P6.6 Notifying breaches and incidents

FedRAMP High · 4 controls

  • IR-5 Incident Monitoring
  • IR-6 Incident Reporting
  • IR-6(1) Automated Reporting
  • IR-7 Incident Response Assistance

FedRAMP Moderate · 4 controls

  • IR-5 Incident Monitoring
  • IR-6 Incident Reporting
  • IR-6(1) Automated Reporting
  • IR-7 Incident Response Assistance

ISO 27002:2022 · 4 controls

  • 5.25 Assessment and decision on information security events
  • 5.26 Response to information security incidents
  • 5.5 Contact with authorities
  • 6.8 Information security event reporting

C5 (Germany) · 3 controls

  • C5-OPS-21 Involvement of Cloud Customers in the Event of Incidents
  • C5-SIM-03 Documentation and reporting of security incidents
  • C5-SIM-04 Duty of the users to report security incidents to a central body

CIS Controls v8 · 3 controls

  • CIS-17.2 Establish and Maintain Contact Information for Reporting Security Incidents
  • CIS-17.3 Establish and Maintain an Enterprise Process for Reporting Incidents
  • CIS-17.6 Define Mechanisms for Communicating During Incident Response

NIST SP 800-161 Rev 1 · 3 controls

NIST SP 800-53 Rev 5 · 3 controls

  • CPS230-27 Identification and Escalation of Incidents and Near Misses
  • CPS230-P33 APRA Notification of Operational Risk Incidents within 72 Hours

APRA CPS 234 · 2 controls

  • CPS234-35 APRA Notification of Material Incidents within 72 Hours
  • CPS234-P25 Response Plan Content and Escalation Mechanisms
  • SEC10-BP01 Identify key personnel and external resources
  • SEC10-BP08 Establish a framework for learning from incidents
  • ASBv3-IR-2 Preparation - setup incident notification
  • ASBv3-IR-3 Detection and analysis - create incidents based on high-quality alerts

HIPAA Security Rule · 2 controls

NIST SP 800-66 Rev 2 · 2 controls

PCI DSS 4.0 · 2 controls

  • 12.10.3 12.10.3 Incident response personnel available 24/7
  • 12.10.5 12.10.5 Plan covers alerts from security monitoring systems
  • E8-APP-ML3 Application Control (ML3)
  • ANSSI-HYG-40 Define a Security Incident Management Procedure

CMMC 2.0 · 1 control

ISO 27701:2019 · 1 control

  • 6.13.1 Management of information security incidents and improvements

NIS2 Directive · 1 control

  • Art.23.1 Notify significant incidents to the CSIRT or competent authority, and warn affected service recipients

NIST SP 800-172 · 1 control

  • 3.6.1e Establish Security Operations Center (SOC)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in 03.06 IR (Incident Response)

You are reading one control. How much of NIST SP 800-171 Rev 3 have you already done?

NIST SP 800-171 Rev 3 03.06.02 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST SP 800-171 Rev 3 your existing evidence covers. Hold PCI DSS 4.0 and 69 of 97 NIST SP 800-171 Rev 3 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the PCI DSS 4.0 pair alone.

Query this from an agent

The graph holds this control, the 63 it maps to, and the evidence behind each claim, over MCP and REST.