NIST SP 800-53 Rev 5
IR - Incident Response

NIST SP 800-53 Rev 5 NIST800-IR-9: IR-9 Information Spillage Response

Respond to information spills by: a. Assigning [Assignment: organization-defined personnel or roles] with responsibility for responding to information spills; b. Identifying the specific information involved in the system contamination; c. Alerting [Assignment: organization-defined personnel or roles] of the information spill using a method of communication not associated with the spill; d. Isolating the contaminated system or system component; e. Eradicating the information from the contaminated system or component; f. Identifying other systems or system components that may have been subsequently contaminated; and g. Performing the following additional actions: [Assignment: organization-defined actions].

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 33 controls across 13 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-DE.AE-04 The estimated impact and scope of adverse events are understood
  • NIST-CSF-RS.AN-07 Incident data and metadata are collected, and their integrity and provenance are preserved
  • NIST-CSF-RS.CO-02 Internal and external stakeholders are notified of incidents
  • NIST-CSF-RS.MA-01 The incident response plan is executed in coordination with relevant third parties once an incident is declared
  • NIST-CSF-RS.MI-01 Incidents are contained

CIS Controls v8 · 4 controls

  • CIS-14.6 Train Workforce Members on Recognizing and Reporting Security Incidents
  • CIS-17.1 Designate Personnel to Manage Incident Handling
  • CIS-17.4 Establish and Maintain an Incident Response Process
  • CIS-17.5 Assign Key Roles and Responsibilities

FedRAMP High · 4 controls

  • IR-9 Information Spillage Response (IR-9)
  • IR-9(2) Information Spillage Response | Training (IR-9(2))
  • IR-9(3) Information Spillage Response | Post-spill Operations (IR-9(3))
  • IR-9(4) Information Spillage Response | Exposure to Unauthorized Personnel (IR-9(4))

FedRAMP Moderate · 4 controls

  • IR-9 Information Spillage Response (IR-9)
  • IR-9(2) Information Spillage Response | Training (IR-9(2))
  • IR-9(3) Information Spillage Response | Post-spill Operations (IR-9(3))
  • IR-9(4) Information Spillage Response | Exposure to Unauthorized Personnel (IR-9(4))

ISO 27001:2022 · 4 controls

  • 5.24 Information security incident management planning and preparation 
  • 5.25 Assessment and decision on information security events
  • 5.26 Response to information security incidents
  • 5.28 Collection of evidence

ISO 27002:2022 · 4 controls

  • 5.24 Information security incident management planning and preparation
  • 5.25 Assessment and decision on information security events
  • 5.26 Response to information security incidents
  • 5.28 Collection of evidence

SOC 2 · 2 controls

  • SOC2-CC7.4 CC7.4 Responding to security incidents
  • SOC2-P6.3 P6.3 Record of unauthorised disclosures and breaches
  • DP-2 Monitor anomalies and threats targeting sensitive data

ISO 27701:2019 · 1 control

  • 6.13.1 Management of information security incidents and improvements

PCI DSS 4.0 · 1 control

  • 12.10.7 12.10.7 Response procedures for PAN found in unexpected locations

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in IR - Incident Response

You are reading one control. How much of NIST SP 800-53 Rev 5 have you already done?

NIST SP 800-53 Rev 5 NIST800-IR-9 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST SP 800-53 Rev 5 your existing evidence covers. Hold ISO 27001:2022 and 163 of 1014 NIST SP 800-53 Rev 5 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 342 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 33 it maps to, and the evidence behind each claim, over MCP and REST.