NIST SP 800-53 Rev 5
IR - Incident Response

NIST SP 800-53 Rev 5 NIST800-IR-8: IR-8 Incident Response Plan

a. Develop an incident response plan that: 1. Provides the organization with a roadmap for implementing its incident response capability; 2. Describes the structure and organization of the incident response capability; 3. Provides a high-level approach for how the incident response capability fits into the overall organization; 4. Meets the unique requirements of the organization, which relate to mission, size, structure, and functions; 5. Defines reportable incidents; 6. Provides metrics for measuring the incident response capability within the organization; 7. Defines the resources and management support needed to effectively maintain and mature an incident response capability; 8. Addresses the sharing of incident information; 9. Is reviewed and approved by [Assignment: organization-defined personnel or roles] [Assignment: organization-defined frequency]; and 10. Explicitly designates responsibility for incident response to [Assignment: organization-defined entities, personnel, or roles]. b. Distribute copies of the incident response plan to [Assignment: organization-defined incident response personnel (identified by name and/or by role) and organizational elements]; c. Update the incident response plan to address system and organizational changes or problems encountered during plan implementation, execution, or testing; d. Communicate incident response plan changes to [Assignment: organization-defined incident response personnel (identified by name and/or by role) and organizational elements]; and e. Protect the incident response plan from unauthorized disclosure and modification.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 88 controls across 35 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-DE.AE-04 The estimated impact and scope of adverse events are understood
  • NIST-CSF-DE.AE-08 Incidents are declared when adverse events meet the defined incident criteria
  • NIST-CSF-GV.SC-08 Relevant suppliers and other third parties are included in incident planning, response, and recovery activities
  • NIST-CSF-ID.IM-04 Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved
  • NIST-CSF-RC.CO-03 Recovery activities and progress in restoring operational capabilities are communicated to designated internal and external stakeholders
  • NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process
  • NIST-CSF-RC.RP-02 Recovery actions are selected, scoped, prioritized, and performed
  • NIST-CSF-RS.MA-01 The incident response plan is executed in coordination with relevant third parties once an incident is declared
  • NIST-CSF-RS.MA-03 Incidents are categorized and prioritized
  • NIST-CSF-RS.MA-04 Incidents are escalated or elevated as needed
  • NIST-CSF-RS.MI-01 Incidents are contained

CIS Controls v8 · 6 controls

  • CIS-17.1 Designate Personnel to Manage Incident Handling
  • CIS-17.4 Establish and Maintain an Incident Response Process
  • CIS-17.5 Assign Key Roles and Responsibilities
  • CIS-17.6 Define Mechanisms for Communicating During Incident Response
  • CIS-17.8 Conduct Post-Incident Reviews
  • CIS-17.9 Establish and Maintain Security Incident Thresholds

PCI DSS 4.0 · 6 controls

  • 12.10.1 12.10.1 Incident response plan ready for activation
  • 12.10.2 12.10.2 Annual review and testing of the incident response plan
  • 12.10.3 12.10.3 Incident response personnel available 24/7
  • 12.10.5 12.10.5 Plan covers alerts from security monitoring systems
  • 12.10.6 12.10.6 Plan evolved from lessons learned and industry developments
  • 12.10.7 12.10.7 Response procedures for PAN found in unexpected locations

SOC 2 · 6 controls

  • SOC2-A1.3 A1.3 Testing recovery plan procedures
  • SOC2-CC7.3 CC7.3 Evaluating security events to identify incidents
  • SOC2-CC7.4 CC7.4 Responding to security incidents
  • SOC2-CC7.5 CC7.5 Recovering from security incidents
  • SOC2-CC9.1 CC9.1 Mitigating risks of business disruption
  • SOC2-P6.6 P6.6 Notifying breaches and incidents

APRA CPS 234 · 4 controls

  • CPS234-32 Annual Review and Testing of Response Plans
  • CPS234-P24 Information Security Response Plans
  • CPS234-P25 Response Plan Content and Escalation Mechanisms
  • 24 Para 24 Maintain information security response plans

ISO 27002:2022 · 4 controls

  • 5.24 Information security incident management planning and preparation
  • 5.26 Response to information security incidents
  • 5.27 Learning from information security incidents
  • 5.29 Information security during disruption
  • ASBv3-IR-1 Preparation - update incident response plan and handling process
  • ASBv3-IR-5 Detection and analysis - prioritize incidents
  • ASBv3-IR-7 Post-incident activity - conduct lesson learned and retain evidence

DORA · 3 controls

FedRAMP High · 3 controls

  • IR-2 Incident Response Training
  • IR-3 Incident Response Testing
  • IR-8 Incident Response Plan

FedRAMP Moderate · 3 controls

  • IR-2 Incident Response Training
  • IR-3 Incident Response Testing
  • IR-8 Incident Response Plan

ISO 22301:2019 · 3 controls

ISO 27701:2019 · 3 controls

  • 6.13 Information security incident management
  • 6.13.1 Management of information security incidents and improvements
  • 6.14 Information security aspects of business continuity management

CMMC 2.0 · 2 controls

EU AI Act · 2 controls

HIPAA Security Rule · 2 controls

ISO 27001:2022 · 2 controls

  • 5.24 Information security incident management planning and preparation 
  • 5.26 Response to information security incidents

NIS2 Directive · 2 controls

  • Art.21.2.b Incident handling
  • Art.23.1 Notify significant incidents to the CSIRT or competent authority, and warn affected service recipients

NIST SP 800-66 Rev 2 · 2 controls

  • E8-ADMIN-ML2 Restrict Administrative Privileges (ML2)
  • ANSSI-HYG-40 Define a Security Incident Management Procedure
  • CPS230-27 Identification and Escalation of Incidents and Near Misses

C5 (Germany) · 1 control

  • C5-SIM-01 Policy for security incident management
  • CFTC-SS-16 Security Incident Response Plan and Testing

GDPR · 1 control

  • GDPR-Art.33 Notification of a personal data breach to the supervisory authority

ISO/IEC 42001:2023 · 1 control

  • A.8.4 Communication of incidents
  • IR-8 IR-8 Incident Response Plan
  • IR-8 IR-8 Incident Response Plan
  • IR-8 IR-8 Incident Response Plan

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in IR - Incident Response

You are reading one control. How much of NIST SP 800-53 Rev 5 have you already done?

NIST SP 800-53 Rev 5 NIST800-IR-8 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST SP 800-53 Rev 5 your existing evidence covers. Hold ISO 27001:2022 and 163 of 1014 NIST SP 800-53 Rev 5 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 342 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 88 it maps to, and the evidence behind each claim, over MCP and REST.