Frameworks / UK Defence Standard 05-138 - Cyber Security for Defence Suppliers / D.1 UK Defence Standard 05-138 - Cyber Security for Defence Suppliers
DEFSTAN 05-138 Section D: Minimising the Impact of Incidents
UK Defence Standard 05-138 - Cyber Security for Defence Suppliers D.1: Incident Response Planning The supplier must have capabilities to minimise the adverse impact of a cyber security incident on operations and data protection.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 445 controls across 162 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
CH-FADP-16 Record keeping and accountability CH-FADP-17 Workplace and employment data CH-FADP-19 Transparency and proactive information CH-FADP-21 Data protection impact assessments FADP-15 Data Breach Notification FADP-16 FDPIC Independence and Functions FADP-7 Data Protection Impact Assessment (Articles 9-10) FADP-9 Data Protection Advisor (Articles 14-15) NDPA-1 Applicability, Scope, and Carve-Outs NDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal NDPA-4 Sensitive Data Processing Consent and Childrens Protections NDPA-5 Privacy Notice, Data Minimisation, and Purpose Limitation NDPA-6 Reasonable Security Practices and Incident Response NDPA-7 Data Protection Assessments and Processor Contracts NDPA-8 Nebraska Attorney General Enforcement, Permanent 30-Day Cure, and Penalties NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission NG-NDPA-2 Lawful Basis, Consent, and Data Protection Principles NG-NDPA-4 Data Subject Rights and Automated Decision-Making NG-NDPA-5 Security of Processing, Breach Notification, and DPIA NG-NDPA-6 Data Protection Officer, DPCO, and Processor Agreements NG-NDPA-7 Cross-Border Data Transfers and International Cooperation NG-NDPA-8 Enforcement, Penalties, Data Controllers of Major Importance (DCMI), and Compliance MTCS-Acquisition-Development-Maintenance-Supplier-Vulnerability-DevSecOps-SBOM-SDLC-SCA-API-Container MTCS Acquisition + Development + Maintenance + Supplier + Vulnerability + DevSecOps + SBOM + SDLC + SCA MTCS-Incident-Business-Continuity-CSC-Data-Protection-72-Hour-Notification-BCP-DR-PDPA MTCS Incident + Business Continuity + CSC Data Protection + 72-Hour Notification + BCP + DR + PDPA MTCS-Logging-Monitoring-Compliance-Audit-SLA-Configuration-SIEM-SOAR-Cloud-Monitoring-CSPM MTCS Logging + Monitoring + Compliance + Audit + SLA + Configuration + SIEM + SOAR + CSPM MTCS-Operations-Physical-Network-Tier-III-Data-Centre-Hardening-Patching-Network-Segmentation-DDoS MTCS Operations + Physical + Network + Tier III Data Centre + Hardening + Patching + Segmentation + DDoS NJDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal NJDPA-6 Reasonable Data Security and Incident Response NJDPA-7 Data Protection Assessments and Processor Contracts NJDPA-8 AG Platkin Enforcement, 18-Month Cure Sunset, and Division of Consumer Affairs SA-PDPL-16 Data breach notification requirements SA-PDPL-17 Security incident response procedures SA-PDPL-19 Data protection officer designation SA-PDPL-21 Data protection impact assessments TRINIDAD-1 Scope, Definitions, Commission TRINIDAD-3 Data Subject Rights TRINIDAD-4 Security, Accuracy TRINIDAD-5 Enforcement and Sanctions API1164-17 Wireless and Field Communications API1164-18 Field Device Security API1164-19 Safety Instrumented Systems Interface ASD37-27 Outbound data loss prevention (Very Good) ASD37-31 Hunt to discover incidents (Very Good) ASD37-33 Capture network traffic (Limited) AT-DSG-10 Section 29 - Liability and right to compensation / civil jurisdiction AT-DSG-12 Section 62 - Administrative penalties AT-DSG-7 Section 18 - Establishment of the Data Protection Authority BSI-18 Incident response planning and testing BSI-20 Incident reporting and notification BSI-21 Forensic analysis capabilities BB-DPA-1 Section 1 - Short Title BB-DPA-20 Sections 50-60 - Registration and Responsibilities BB-DPA-4 Section 4 - Principles Relating to Processing IS.AR.215 Information Security Incident Response IS.D.OR.225 External Reporting of Information Security Events IS.I.OR.225 External Reporting Part11.30 Controls for open systems (21 CFR §11.30) Part11.AuditTrail Audit trail requirements - secure computer-generated time-stamped (21 CFR §11.10(e)) Part11.RecordRetention Record protection + retention + readiness for inspection (21 CFR §11.10(b) + (c)) FFIEC-23 Regulatory reporting requirements FFIEC-24 Customer notification procedures FFIEC-25 Post-incident review and improvement GhCSA-Cybercrime-Lawful-Access-Preservation Cybercrime Offences, Lawful Access and Electronic Evidence Preservation GhCSA-Implementation-Roadmap Implementation Roadmap - Organizational Roles, Tooling and Metrics GhCSA-Incident-Reporting-CERT-GH Cybersecurity Incident Reporting (24-Hour to CSA) and National CERT-GH Engagement IEC62443-16 Incident response plan for operational disruptions IEC62443-17 Recovery plan for critical systems IEC62443-20 Exercises and drills for OT incidents ISO-22320-5.2 Incident management process ISO-22320-B Annex B: Incident management plan structure ISO-22320-C Annex C: Incident management task examples ISO27799-03 Minimum necessary standard enforcement ISO27799-04 Patient data de-identification procedures ISO27799-05 Audit trail for ePHI access 27011-5.2 Information Security Roles in Telecoms 27011-6.3 Awareness and Training 27011-8.6 Data protection and backup ISO27019-16 Incident response plan for operational disruptions ISO27019-18 Reporting obligations to authorities ISO27019-20 Exercises and drills for OT incidents 27400-6.5 Security monitoring and incident response 27400-7.1 Network Security for IoT 27400-7.4 Data retention and deletion MY-PDPA-Cross-Border-Transfer-Section-129-Whitelist-Abolition-2024-Adequacy-SCC-BCR-Processor-Direct-Marketing Malaysia PDPA Cross-Border + Section 129 + Whitelist Abolition 2024 + Adequacy + SCC + BCR + Processor + Marketing MY-PDPA-DPO-Designation-Class-Data-User-Registration-DPIA-Code-Practice-Section-43A-2024-Amendment Malaysia PDPA Governance + DPO Section 43A + Class of Data User Registration + DPIA + Code of Practice MY-PDPA-Security-Principle-Retention-Data-Integrity-Breach-Notification-72-Hour-Section-12B-2024-Amendment Malaysia PDPA Security + Retention + Data Integrity + Breach Notification 72 Hour + Section 12B + 2024 Amendment MU-DPA-Cross-Border-Transfer-Section-36-Adequacy-SCC-BCR-Mauritius-Global-Business-IBC-Financial-Services Mauritius DPA Cross-Border + Section 36 + Adequacy + SCC + BCR + Mauritius Global Business + Financial Services MU-DPA-Governance-DPO-Designation-Section-25-DPO-ROPA-DPIA-Codes-Section-38-Commissioner-Registration Mauritius DPA Governance + DPO + ROPA + DPIA + Codes Section 38 + Commissioner Registration MU-DPA-Security-Breach-Notification-Section-25-BREACH-72-Hour-Commissioner-Cyber-Security-Strategy Mauritius DPA Security + Breach Notification + Section 25-BREACH + 72 Hour + Commissioner + Cyber Security Strategy MX-LFPDPPP-Cross-Border-Transfer-Articles-36-37-Reglamento-66-68-Domestic-International-APEC-CBPR-USMCA Mexico LFPDPPP Cross-Border + Articles 36-37 + Reglamento 66 + 68 + Domestic + International + APEC CBPR + USMCA MX-LFPDPPP-Governance-Officer-Reglamento-47-50-Security-Manual-57-Risk-Assessment-61-Self-Regulation-Parameters-2014 Mexico LFPDPPP Governance + Officer + Reglamento 47 + Security Manual 50 + Risk Assessment 57 + Self-Regulation Parameters 2014 MX-LFPDPPP-Security-Breach-Notification-Reglamento-63-No-Time-Limit-INAI-Recommendations-CERT-MX Mexico LFPDPPP Security + Breach Notification + Reglamento 63 + No Specified Time + INAI Recommendations + CERT-MX NIST-CSF-ID.IM-04 Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process NIST-CSF-RS.MA-01 The incident response plan is executed in coordination with relevant third parties once an incident is declared NISTPF-4 Communicate-P - Privacy Notice, Transparency, and Individual Awareness NISTPF-7 Protect-P Maintenance and Protective Technology (PR.MA-P, PR.PT-P) NISTPF-8 Protect-P Information Protection Processes (PR.PO-P) NISTSP144-3 Data Classification, Handling, and Sovereignty NISTSP144-5 Identity and Access in Cloud, Federation, and Privileged Access NISTSP144-8 Monitoring, Incident Response, Exit Strategy, and Compliance NIST800-IR-2 IR-2 Incident Response Training NIST800-IR-5 IR-5 Incident Monitoring NIST800-IR-7 IR-7 Incident Response Assistance NHPA-6 Reasonable Data Security and Breach Response NHPA-7 Data Protection Assessments and Processor Contracts NHPA-8 AG Formella Enforcement, Permanent 60-Day Cure, and Penalties OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery OSFIB13-7 Incident Reporting to OSFI and Regulatory Coordination OSFIB13-8 Metrics, Monitoring, Continuous Improvement, Maturity OREGONCPA-3 Consent, Sensitive Data, Children and Teen Protections OREGONCPA-5 Data Protection Assessments, Privacy by Design, Security Practices OREGONCPA-8 Cure Period, Attorney General Enforcement, Training, Compliance Monitoring PCI-P2PE-21 Incident detection and classification PCI-P2PE-22 Incident response and containment PCI-P2PE-25 Post-incident review and improvement PCI-PIN-23 Regulatory reporting requirements PCI-PIN-24 Customer notification procedures PCI-PIN-25 Post-incident review and improvement PCI-SSF-21 Incident detection and classification PCI-SSF-24 Customer notification procedures PCI-SSF-25 Post-incident review and improvement PDPASG-1 Accountability, Records, DPO Appointment, and Training PDPASG-4 Children's Data, DPIA, and Privacy by Design PDPASG-8 Data Breach Notification, Incident Response, and Enforcement PDPATH-4 DPIA, Privacy by Design, Children's Data PDPATH-7 DPO, Records of Processing, Retention, Marketing, Training PDPATH-8 Data Breach Notification, Complaints, Compliance, Enforcement POPIASA-4 Special Personal Information, Children, Information Quality, Documentation POPIASA-5 Security Safeguards, Encryption, Access Control, Operator Obligations POPIASA-7 Information Officer, Records of Processing, Notification, Training NORWAY-4 DPIA, Privacy by Design, Records of Processing NORWAY-7 DPO, Cooperation with Datatilsynet, Retention, Marketing, Training NORWAY-8 Breach Notification, Complaints, Compliance, Enforcement PERU-3 Data Subject Rights (ARCO), Habeas Data, Automated Decisions PERU-7 DPO, Records, Retention, Marketing, Training PERU-8 Breach Notification, ANPD Cooperation, Sanctions, Compliance NZPRV-6 IPP 13 Unique Identifiers, Privacy Impact Assessment, Privacy by Design NZPRV-7 Notifiable Privacy Breach Scheme NZPRV-8 Privacy Officer, OPC Cooperation, Compliance Notices, Complaints, Training QATAR-5 Security of Processing QATAR-7 DPO, Records, Retention, Marketing, Training QATAR-8 Breach Notification, Compliance, Enforcement PICERL-C2 System Backup PICERL-C3 Long-Term Containment PICERL-L3 Plan Improvement SOCI-CIRMP-PHYSICAL CIRMP hazard vector: Physical security and natural hazards SOCI-S30CB Statutory incident response planning SOCI-S35AB Ministerial authorisation for government assistance IM8-DAT.2 Data Protection IM8-DAT.4 Data Retention and Disposal IM8-RES.3 Incident Response UGA-3 Accountability Principle UGA-6 Personal Data Protection Office UGA-7 Data Protection Officer APPI-A41 Preparation and Handling of Pseudonymized Personal Information APPI-A43 Preparation of Anonymized Personal Information CPS234-21 Implementation of Information Security Controls CPS234-25 Internal Audit Review of Information Security Controls AZ-DPA-15 Article 17 - Dispute resolution AZ-DPA-6 Article 6 - State regulation in personal data protection LOPDP-EC-Governance-DPO-ROPA-DPIA-Privacy-by-Design-Training-Articles-46-58-Compliance-Monitoring Ecuador LOPDP Governance + DPO + ROPA + DPIA + Privacy by Design + Training LOPDP-EC-Security-Processor-Breach-Notification-Articles-37-45-Encryption-72-Hour-SPDP-Notification-CSIRT Ecuador LOPDP Security + Processor + Breach Notification + Articles 37-45 + 72-Hour FISMA-3554-Agency-Responsibilities Federal Agency Responsibilities (44 USC 3554) - CIO + CISO + Program + Reporting FISMA-NIST-800-53-RMF-800-171-FIPS Operationalisation via NIST 800-53 + 800-37 RMF + 800-171 + FIPS 199 + FIPS 200 FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) FTC-Safeguards-IR-Plan-BoardReporting-FTC-Notification Written Incident Response Plan + Board Reporting + FTC Breach Notification (16 CFR 314.4(h), (i), (j)) FedRAMP-Boundary Authorization Boundary, SSP, SAR, POA&M documentation FedRAMP-IncidentReporting FedRAMP incident reporting to PMO and US-CERT UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10) UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21) GLBA-Implementation-Roadmap-Examination GLBA Implementation Roadmap, Examination Readiness, Roles and Tooling GLBA-Status-FTC-CFPB-SEC-NAIC-Enforcement GLBA Status, Enforcement Activity, FTC + CFPB + SEC + NAIC Recent Actions IACS-UR-E26-Respond-Recover-IncidentResponse-Recovery-Backup-Lessons IACS UR E26 Respond + Recover Goals - Incident Response + Communication + Recovery + Backup + Lessons Learned IACS-UR-E27-Logging-Forensics-EventCapture IACS UR E27 - Equipment Logging + Forensic Readiness + Event Capture + Tamper Detection 30111-3 Terms and definitions 30111-5.2 Vulnerability handling team INCDPA-Controller-PrivacyNotice-PurposeLimitation-DataMinimisation-Transparency-LawfulBasis Indiana CDPA Controller Obligations - Privacy Notice + Purpose Limitation + Data Minimisation + Transparency + Lawful Basis + Reasonable + Adequate + Relevant + Limited to What is Necessary INCDPA-Security-ReasonablePractices-Breach-Notification-Records-Encryption-Pseudonymisation Indiana CDPA Security + Reasonable Practices + Breach Notification + Indiana Breach Notification Law (IC 24-4.9) + Records + Encryption + Pseudonymisation + De-Identification JO-PDPL-Personal-Data-Protection-Council-Article4-5-6-Establishment-MoDEE-Functions-Powers-Investigation Jordan PDPL Personal Data Protection Council + Articles 4-5-6 + Establishment + Ministry of Digital Economy and Entrepreneurship (MoDEE) + Functions + Powers + Investigation + Administrative Penalties + Council Composition + International Cooperation JO-PDPL-Training-Awareness-Penalties-Article22-23-24-Compensation-Administrative-Criminal-100K-200K-JOD Jordan PDPL Training + Awareness + Penalties + Articles 22-23-24 + Compensation + Administrative Penalties JOD 100K + JOD 200K Repeat + Criminal 3 Years + Civil Compensation + Director Liability + Reasonable Care Defence LGPD-BR-Governance-Encarregado-DPO-ROPA-DPIA-Privacy-by-Design-Article-46-50-Codes-of-Conduct Brazil LGPD Governance + Encarregado (DPO) + ROPA + DPIA + Articles 46-50 LGPD-BR-Security-Article-46-48-Breach-Notification-ANPD-Reasonable-Time-Incident-Response-CSIRT Brazil LGPD Security + Article 46-48 + Breach Notification + ANPD + Incident Response DOM172-Security-Measures-Article-25-Encryption-Pseudonymization-Access-Control-Incident-Handling-Breach-Notification-Article-22 Dominican Republic Law 172-13 Security Measures + Article 25 + Encryption + Breach Notification DOM172-Supervisory-Authority-Cooperation-Sanctions-Penalties-Articles-77-79-Awareness-Training-Retention-DPO-Designation Dominican Republic Law 172-13 Supervisory Authority + Sanctions + Articles 77-79 + DPO + Awareness MDS2-Audit-Logging-AUDT-Integrity-IGAU-Cybersecurity-Risk-CYBR-Monitoring MDS2 Audit Controls + AUDT + Integrity + IGAU + Cybersecurity Risk + CYBR + Continuous Monitoring MDS2-PHI-Data-Handling-DATA-Storage-STCF-Transmission-TXCF-TXIG-Encryption-FIPS MDS2 PHI Handling + DATA + STCF Storage + TXCF Transmission + TXIG Integrity + Encryption + FIPS MN-CDPA-Chief-Privacy-Officer-Section-325O-06-MN-UNIQUE-Designation-Privacy-Programme-Training Minnesota CDPA Chief Privacy Officer + Section 325O.06 + MINNESOTA-UNIQUE Designation + Privacy Programme + Training MN-CDPA-Data-Privacy-Assessment-DPIA-Section-325O-07-Sensitive-Targeted-Sale-Profiling-AI-Consumer-Health Minnesota CDPA DPIA + Section 325O.07 + Sensitive + Targeted + Sale + Profiling + AI + Consumer Health MT-CDPA-Data-Protection-Assessment-MCA-30-14-2815-Sensitive-Targeted-Sale-Profiling-AG-Inspection Montana CDPA Data Protection Assessment + MCA 30-14-2815 + Sensitive + Targeted + Sale + Profiling + AG Inspection MT-CDPA-Sensitive-Data-MCA-30-14-2802-Opt-In-Children-13-Parental-Consent-Minors-13-16-Opt-In Montana CDPA Sensitive Data + MCA 30-14-2802 + Affirmative Opt-In + Children Under 13 Parental + Minors 13-16 Opt-In NISTSP122-6 PII Breach Response and Incident Handling NISTSP122-8 Continuous Monitoring, Training, and Privacy Programme Governance NISTSP145-3 Rapid Elasticity Characteristic and Capacity Management NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition NISTSP146-6 Cloud Security and Privacy Recommendations NISTSP146-7 Service Level, Performance, Reliability, Interoperability, and Portability NRFCS-1 Retail Cybersecurity Governance, Policy, and Regulatory Change Management NRFCS-7 Detection, Logging, Incident Response, Breach Notification, and Fraud Detection NGCB-6 Incident Response, 72-Hour NGCB Notification, and Independent Investigation NGCB-7 Patron and Employee Data Protection + Data Inventory + Vendor Management NGNDPR-5 Security of Personal Data, Breach Notification, and DPIA under NDPR Section 2.6-Security NGNDPR-6 Data Protection Officer, DPCOs, and Processor Obligations OMANCS-4 Data Protection, Cryptography, and Privacy Alignment OMANCS-6 Security Monitoring, Detection, Incident Response, and OmanCERT Notification OPENBANK-7 Logging, Monitoring, Regulatory Reporting, SLA, Availability OPENBANK-8 Incident Detection, Response, Customer Notification, Post-Incident Review, BCM PSDTWO-3 Common and Secure Communication, API Access for AISPs and PISPs PSDTWO-4 Fraud Reporting and Incident Management SOC2-CC7.4 CC7.4 Responding to security incidents SOC2-CC7.5 CC7.5 Recovering from security incidents SOC-CY-C2 Encryption and Data Protection SOC-CY-S2 System Operations SSAE18-CC7.4 CC7.4 - Incident Response SSAE18-CC7.5 CC7.5 - Incident Recovery PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33 PIPA-Sensitive-Information-Unique-ID-Resident-Registration-Numbers-CCTV-Articles-23-24-25 Korea PIPA Sensitive Information + Unique ID + RRN + CCTV + Articles 23-25 SWE-1 Scope and Purpose SWE-2 Relationship to GDPR TANZANIA-1 Scope, Registration, Lawful Basis TANZANIA-4 Security and Cross-Border TSSR-INFO-1 Network Data Protection TSSR-NOT-2 Security Incident Notification TEXASTDPSA-2 Consumer Rights TEXASTDPSA-3 Sensitive Data, Children, Sale Notice TURKEYKVKK-2 Information Notice and Data Subject Rights TURKEYKVKK-3 Special Categories and Sensitive Data Standard 15 Online Tools Standard 2 Data Protection Impact Assessments UKGDPRREG-2 Data Subject Rights (Articles 12-22) UKGDPRREG-3 Controller and Processor (Articles 24-43) URUGUAY-4 Security and Cross-Border URUGUAY-5 Database Registration with AGESIC URCDP VIETNAMPDP-2 Consent and Notice VIETNAMPDP-3 Data Subject Rights PMF-M.4 Privacy Incident Management CPS230-13 Board Accountability for Operational Risk Management 4.4.7 Emergency and Incident Response AWWA-3.4 Encryption and Data Protection AL-DPA-14 Direct Marketing CPG-3.C Strong and Agile Encryption CA-12 Deploys Through Policies and Procedures CA-ITSG33-SC-01 Security Control Catalogue CAT-D5-1 Incident planning and strategy FIRST-CSIRTF-SA2-ISIM Service Area 2 - Information Security Incident Management (Intake, Analysis, Containment, Recovery, Coordination, Crisis) FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711) HITECH-SubtitleD-Breach-Notification-BA-Direct-Liability HITECH Subtitle D - Breach Notification Rule (45 CFR Part 164 Subpart D), Business Associate Direct Liability, Subcontractors HKMA-SPM-TM-Technology-TM-G-1-CRAF-Coord HKMA SPM Technology Management Modules (TM-G-1 to TM-G-4, TM-E-1) + Coordination with C-RAF IEEE1686-IR-Recovery-Reporting-Exercises-Drills-RECOV IEEE 1686 - Incident Response + Recovery from Failed Update + Reporting to Authorities + Coordination with Sector-Specific Agencies + Exercises and Drills IEEE7000-Operations-Lifecycle-OngoingMonitoring-Incident-Decommissioning IEEE 7000 - Operations + Lifecycle + Ongoing AI Risk Monitoring + Data Provenance + Retention + Privacy + Safe Deployment + Decommissioning + Disposal ISO-26000-6.7 Consumer issues ISO28001-PC-04 Supply Chain Continuity Planning ISO20000-11 Incident management ISO23894-A.5 Privacy and Data Protection in AI 27010-16.1 Continuity of Sharing ITIL4-11 Incident management JP-AIG-Data-Governance-Training-Data-Quality-Provenance-Lineage-Copyright-APPI-Personal-Information-Protection Japan AI Guidelines Data Governance + Training Data Quality + Provenance + Lineage + Copyright Act 2018 Article 30-4 Text Data Mining Exception + APPI 2022 Amendment + Personal Information Protection + Privacy Principle JP-FSA-CYB-Incident-Response-Playbooks-Containment-Eradication-Recovery-Post-Mortem-Tabletop-CSIRT Japan FSA Cybersecurity Incident Response + Playbooks + Containment + Eradication + Recovery + Post-Mortem + Tabletop Exercises + CSIRT + FSA Notification + Customer Communication + Forensics + Lessons Learned LAOS-CC-LaoCERT-Incident-Response-National-Cybersecurity-Coordination-Article-22 Laos Cybercrime LaoCERT + Incident Response + National Cybersecurity Coordination + Article 22 MAS-TRM-Cyber-Resilience-Chapter-11-Threat-Intelligence-Penetration-Testing-Incident-Response-1-Hour-Notification MAS TRM Cyber Resilience + Chapter 11 + Threat Intelligence + Penetration Testing + Incident Response + 1-Hour Notification NERCCIP-6 Incident Reporting and Response Planning + Recovery Plans (CIP-008 + CIP-009) NFPA1600-6.3 Emergency Response Operations NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication NISTSP82-7 OT Incident Response, Forensics, Recovery, and Continuity NGOB-5 Fraud Monitoring, Incident Notification, and Reporting to CBN OECDAI-5 Data Governance, Training Data Quality, Privacy, and Bias Mitigation DSOMM-1 Culture, Organization, Education, and Governance PASONE-6 Incident Management, Audit, Handover, Operational Phase, Decommissioning PNGCYBER-4 Incident Response, Investigation, Evidence Preservation, Data Retention PARAGUAY-5 Security of Processing, Data Integrity, Information Security PSPF24-1 Security Culture, Governance, Risk Management ISMSP-SYS-05 Incident Response STUDPRV-2 Data Subject Rights for Students and Parents TEF-2 Openness and Transparency TSAPIPE-2 OT/IT Network Segmentation and Access Control TAIWAN-3 Data Subject Rights UKAI-2 Sector-Specific Regulator Engagement UKGAMBLE-4 Resilience and Incident Response OB-OPS.4 Incident Management UK-TSA-MON-02 Incident Notification UNESCOAI-2 Principles 4-7: Sustainability, Privacy, Human Oversight, Transparency UNICEFAI-4 Transparency, Explanation, Adult Capacity CPSC-CS.3 Data Protection for Safety Systems US-ITAR-EAR-DS-01 Technical Data Protection CYB-5 Cyber Incident Response Plan VIRGINIAVCDPA-3 Sensitive Data Consent and Children VPSHR-3 Implementation Guidance and Reporting Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in DEFSTAN 05-138 Section D: Minimising the Impact of Incidents Query this from an agent The graph holds this control, the 445 it maps to, and the evidence behind each claim, over MCP and REST.