NIST SP 800-53 Rev 5
IR - Incident Response

NIST SP 800-53 Rev 5 NIST800-IR-6: IR-6 Incident Reporting

a. Require personnel to report suspected incidents to the organizational incident response capability within [Assignment: organization-defined time period]; and b. Report incident information to [Assignment: organization-defined authorities].

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 91 controls across 42 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-DE.AE-06 Information on adverse events is provided to authorized staff and tools
  • NIST-CSF-DE.AE-08 Incidents are declared when adverse events meet the defined incident criteria
  • NIST-CSF-GV.RM-05 Lines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties
  • NIST-CSF-RC.CO-03 Recovery activities and progress in restoring operational capabilities are communicated to designated internal and external stakeholders
  • NIST-CSF-RC.CO-04 Public updates on incident recovery are shared using approved methods and messaging
  • NIST-CSF-RS.AN-07 Incident data and metadata are collected, and their integrity and provenance are preserved
  • NIST-CSF-RS.CO-02 Internal and external stakeholders are notified of incidents
  • NIST-CSF-RS.CO-03 Information is shared with designated internal and external stakeholders
  • NIST-CSF-RS.MA-02 Incident reports are triaged and validated
  • NIST-CSF-RS.MA-04 Incidents are escalated or elevated as needed

SOC 2 · 6 controls

  • SOC2-CC2.3 CC2.3 Communication with external parties about internal control (COSO principle 15)
  • SOC2-CC4.2 CC4.2 Evaluating and communicating control deficiencies (COSO principle 17)
  • SOC2-CC7.4 CC7.4 Responding to security incidents
  • SOC2-P6.3 P6.3 Record of unauthorised disclosures and breaches
  • SOC2-P6.5 P6.5 Vendor commitments to report unauthorised disclosures
  • SOC2-P6.6 P6.6 Notifying breaches and incidents

CIS Controls v8 · 5 controls

  • CIS-13.1 Centralize Security Event Alerting
  • CIS-14.6 Train Workforce Members on Recognizing and Reporting Security Incidents
  • CIS-17.2 Establish and Maintain Contact Information for Reporting Security Incidents
  • CIS-17.3 Establish and Maintain an Enterprise Process for Reporting Incidents
  • CIS-17.6 Define Mechanisms for Communicating During Incident Response

NIST SP 800-150 · 5 controls

ISO 27001:2022 · 4 controls

  • 5.24 Information security incident management planning and preparation 
  • 5.26 Response to information security incidents
  • 5.5 Contact with authorities
  • 6.8 Information security event reporting
  • CPS230-27 Identification and Escalation of Incidents and Near Misses
  • CPS230-P33 APRA Notification of Operational Risk Incidents within 72 Hours
  • CPS230-P42 APRA Notification of Disruption Outside Tolerance within 24 Hours

C5 (Germany) · 3 controls

  • C5-OPS-21 Involvement of Cloud Customers in the Event of Incidents
  • C5-SIM-03 Documentation and reporting of security incidents
  • C5-SIM-04 Duty of the users to report security incidents to a central body

DORA · 3 controls

FedRAMP High · 3 controls

  • IR-6 Incident Reporting
  • IR-6(1) Automated Reporting
  • IR-6(3) Incident Reporting | Supply Chain Coordination (IR-6(3))

FedRAMP Moderate · 3 controls

  • IR-6 Incident Reporting
  • IR-6(1) Automated Reporting
  • IR-6(3) Incident Reporting | Supply Chain Coordination (IR-6(3))

HIPAA Security Rule · 3 controls

EU AI Act · 2 controls

  • EUAI-Art.55 Obligations of providers of GPAI models with systemic risk
  • EUAI-Art.73 Reporting of serious incidents

GDPR · 2 controls

  • GDPR-Art.33 Notification of a personal data breach to the supervisory authority
  • GDPR-Art.34 Communication of a personal data breach to the data subject

ISO 27002:2022 · 2 controls

  • 5.5 Contact with authorities
  • 6.8 Information security event reporting

ISO 27701:2019 · 2 controls

  • 6.13 Information security incident management
  • 6.13.1 Management of information security incidents and improvements

ISO/IEC 42001:2023 · 2 controls

  • A.3.3 Reporting of concerns
  • A.8.4 Communication of incidents

PCI DSS 4.0 · 2 controls

  • 12.10.1 12.10.1 Incident response plan ready for activation
  • 12.10.5 12.10.5 Plan covers alerts from security monitoring systems
  • E8-APP-ML2 Application Control (ML2)
  • ANSSI-HYG-40 Define a Security Incident Management Procedure

APPI · 1 control

  • APPI-A26 Report of Leakage to the Commission and Notification to the Person

APRA CPS 234 · 1 control

  • CPS234-35 APRA Notification of Material Incidents within 72 Hours
  • SEC10-BP01 Identify key personnel and external resources
  • ACQS-SIRS Serious Incident Response Scheme
  • ASBv3-IR-2 Preparation - setup incident notification

CMMC 2.0 · 1 control

  • DFARS-7012-c Cyber incident reporting (72-hour rapid report)

ISO 22301:2019 · 1 control

  • 8.4.3 Warning and communication

NIS2 Directive · 1 control

  • Art.23.1 Notify significant incidents to the CSIRT or competent authority, and warn affected service recipients

NIST SP 800-171 · 1 control

  • 03.06.02 Incident Monitoring, Reporting, and Response Assistance
  • IR-6 IR-6 Incident Reporting
  • IR-6 IR-6 Incident Reporting
  • IR-6 IR-6 Incident Reporting

PTES · 1 control

  • PTES-2.2 Agree incident handling and the interaction with the organisation's response team

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in IR - Incident Response

You are reading one control. How much of NIST SP 800-53 Rev 5 have you already done?

NIST SP 800-53 Rev 5 NIST800-IR-6 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST SP 800-53 Rev 5 your existing evidence covers. Hold ISO 27001:2022 and 163 of 1014 NIST SP 800-53 Rev 5 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 342 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 91 it maps to, and the evidence behind each claim, over MCP and REST.