NIST SP 800-53 Rev 5
IR - Incident Response

NIST SP 800-53 Rev 5 NIST800-IR-4: IR-4 Incident Handling

a. Implement an incident handling capability for incidents that is consistent with the incident response plan and includes preparation, detection and analysis, containment, eradication, and recovery; b. Coordinate incident handling activities with contingency planning activities; c. Incorporate lessons learned from ongoing incident handling activities into incident response procedures, training, and testing, and implement the resulting changes accordingly; and d. Ensure the rigor, intensity, scope, and results of incident handling activities are comparable and predictable across the organization.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 148 controls across 49 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-DE.AE-02 Potentially adverse events are analyzed to better understand associated activities
  • NIST-CSF-DE.AE-04 The estimated impact and scope of adverse events are understood
  • NIST-CSF-DE.AE-06 Information on adverse events is provided to authorized staff and tools
  • NIST-CSF-DE.AE-08 Incidents are declared when adverse events meet the defined incident criteria
  • NIST-CSF-ID.IM-03 Improvements are identified from execution of operational processes, procedures, and activities
  • NIST-CSF-ID.RA-08 Processes for receiving, analyzing, and responding to vulnerability disclosures are established
  • NIST-CSF-RS.AN-03 Analysis is performed to establish what has taken place during an incident and the root cause of the incident
  • NIST-CSF-RS.AN-06 Actions performed during an investigation are recorded, and the records' integrity and provenance are preserved
  • NIST-CSF-RS.AN-07 Incident data and metadata are collected, and their integrity and provenance are preserved
  • NIST-CSF-RS.AN-08 An incident's magnitude is estimated and validated
  • NIST-CSF-RS.MA-01 The incident response plan is executed in coordination with relevant third parties once an incident is declared
  • NIST-CSF-RS.MA-02 Incident reports are triaged and validated
  • NIST-CSF-RS.MA-03 Incidents are categorized and prioritized
  • NIST-CSF-RS.MA-04 Incidents are escalated or elevated as needed
  • NIST-CSF-RS.MA-05 The criteria for initiating incident recovery are applied
  • NIST-CSF-RS.MI-01 Incidents are contained
  • NIST-CSF-RS.MI-02 Incidents are eradicated

PCI DSS 4.0 · 13 controls

  • 10.4.3 10.4.3 Exceptions and anomalies from log review addressed
  • 10.7.1 10.7.1 Service providers detect critical control failures (superseded)
  • 10.7.3 10.7.3 Respond promptly to critical security control failures
  • 11.4.4 11.4.4 Correct exploitable findings from penetration tests
  • 11.5.1.1 11.5.1.1 Service providers detect covert malware channels
  • 12.10.1 12.10.1 Incident response plan ready for activation
  • 12.10.2 12.10.2 Annual review and testing of the incident response plan
  • 12.10.3 12.10.3 Incident response personnel available 24/7
  • 12.10.4 12.10.4 Periodic training for incident response personnel
  • 12.10.5 12.10.5 Plan covers alerts from security monitoring systems
  • 12.10.6 12.10.6 Plan evolved from lessons learned and industry developments
  • 12.10.7 12.10.7 Response procedures for PAN found in unexpected locations
  • 5.4.1 5.4.1 Mechanisms detect and protect against phishing

CIS Controls v8 · 11 controls

  • CIS-1.2 Address Unauthorized Assets
  • CIS-16.2 Establish and Maintain a Process to Accept and Address Software Vulnerabilities
  • CIS-16.3 Perform Root Cause Analysis on Security Vulnerabilities
  • CIS-17.1 Designate Personnel to Manage Incident Handling
  • CIS-17.3 Establish and Maintain an Enterprise Process for Reporting Incidents
  • CIS-17.4 Establish and Maintain an Incident Response Process
  • CIS-17.6 Define Mechanisms for Communicating During Incident Response
  • CIS-17.8 Conduct Post-Incident Reviews
  • CIS-17.9 Establish and Maintain Security Incident Thresholds
  • CIS-18.3 Remediate Penetration Test Findings
  • CIS-18.4 Validate Security Measures

FedRAMP High · 7 controls

  • AU-6(3) Correlate Audit Record Repositories
  • IR-1 Policy and Procedures
  • IR-2 Incident Response Training
  • IR-4 Incident Handling
  • IR-4(1) Automated Incident Handling Processes
  • SA-2 Allocation of Resources
  • SI-7(7) Integration of Detection and Response

FedRAMP Moderate · 7 controls

  • AU-6(3) Correlate Audit Record Repositories
  • IR-1 Policy and Procedures
  • IR-2 Incident Response Training
  • IR-4 Incident Handling
  • IR-4(1) Automated Incident Handling Processes
  • SA-2 Allocation of Resources
  • SI-7(7) Integration of Detection and Response

SOC 2 · 7 controls

  • SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16)
  • SOC2-CC6.8 CC6.8 Preventing and detecting unauthorised or malicious software
  • SOC2-CC7.3 CC7.3 Evaluating security events to identify incidents
  • SOC2-CC7.4 CC7.4 Responding to security incidents
  • SOC2-CC7.5 CC7.5 Recovering from security incidents
  • SOC2-P6.3 P6.3 Record of unauthorised disclosures and breaches
  • SOC2-P6.6 P6.6 Notifying breaches and incidents

ISO 27001:2022 · 6 controls

  • 5.24 Information security incident management planning and preparation 
  • 5.25 Assessment and decision on information security events
  • 5.26 Response to information security incidents
  • 5.27 Learning from information security incidents
  • 5.28 Collection of evidence
  • 5.36 Compliance with policies, rules and standards for information security

DORA · 5 controls

ISO 27002:2022 · 5 controls

  • 5.24 Information security incident management planning and preparation
  • 5.25 Assessment and decision on information security events
  • 5.26 Response to information security incidents
  • 5.27 Learning from information security incidents
  • 5.28 Collection of evidence

ISO 27701:2019 · 5 controls

  • 5.8.1 Nonconformity and corrective action
  • 6.12.2 Supplier service delivery management
  • 6.13 Information security incident management
  • 6.13.1 Management of information security incidents and improvements
  • 7.3.9 Handling requests
  • ASBv3-IR-1 Preparation - update incident response plan and handling process
  • ASBv3-IR-4 Detection and analysis - investigate an incident
  • ASBv3-IR-5 Detection and analysis - prioritize incidents
  • ASBv3-IR-6 Containment, eradication and recovery - automate the incident handling

HIPAA Security Rule · 4 controls

ISO 22301:2019 · 4 controls

  • 10.2 Continual improvement
  • 8.4.2 Response structure
  • 8.4.3 Warning and communication
  • 8.4.5 Recovery

NIST SP 800-66 Rev 2 · 4 controls

APRA CPS 234 · 3 controls

  • CPS234-30 Detection and Response Mechanisms
  • CPS234-P25 Response Plan Content and Escalation Mechanisms
  • 23 Para 23 Detect and respond to incidents promptly
  • ASD37-28 Continuous incident detection and response (Excellent)
  • ASD37-30 Endpoint detection and response (Very Good)

C5 (Germany) · 2 controls

EU AI Act · 2 controls

NIST SP 800-172 · 2 controls

  • 3.6.1e Establish Security Operations Center (SOC)
  • 3.6.2e Establish and Maintain a Cyber Incident Response Team
  • E8-APP-ML2 Application Control (ML2)
  • ANSSI-HYG-40 Define a Security Incident Management Procedure

API 1164 · 1 control

  • API1164-12 Incident Response
  • CPS230-27 Identification and Escalation of Incidents and Near Misses
  • ACQS-SIRS Serious Incident Response Scheme
  • CFTC-SS-16 Security Incident Response Plan and Testing

CMMC 2.0 · 1 control

  • SEF-07 Incident Management and Response
  • DODZT-6.7 Security Operations Center and Incident Response
  • EBA-GL-3.5.1 ICT incident and problem management

GDPR · 1 control

  • GDPR-Art.34 Communication of a personal data breach to the data subject

ISO/IEC 42001:2023 · 1 control

  • 10.2 Nonconformity and corrective action

NIS2 Directive · 1 control

NIST SP 800-161 · 1 control

NIST SP 800-171 · 1 control

NIST SP 800-218 · 1 control

  • IR-4 IR-4 Incident Handling
  • IR-4 IR-4 Incident Handling
  • IR-4 IR-4 Incident Handling
  • 3(e)(i)(B) Sec. 3(e)(i)(B) (now 3(c)(i)(B)) Detect, report and recover from anomalous space system activity

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in IR - Incident Response

You are reading one control. How much of NIST SP 800-53 Rev 5 have you already done?

NIST SP 800-53 Rev 5 NIST800-IR-4 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST SP 800-53 Rev 5 your existing evidence covers. Hold ISO 27001:2022 and 163 of 1014 NIST SP 800-53 Rev 5 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 342 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 148 it maps to, and the evidence behind each claim, over MCP and REST.