RS.AN: Analysis
Next Version:
- NIST Cybersecurity Framework v2.0:
- RS.AN: Incident Analysis
Description
Analysis is conducted to ensure effective response and support recovery activities.
Framework Subcategories
RS.AN-1: Notifications from detection systems are investigated
[csf.tools Note: Subcategories do not have detailed descriptions.]
RS.AN-2: The impact of the incident is understood
[csf.tools Note: Subcategories do not have detailed descriptions.]
RS.AN-3: Forensics are performed
[csf.tools Note: Subcategories do not have detailed descriptions.]
RS.AN-4: Incidents are categorized consistent with response plans
[csf.tools Note: Subcategories do not have detailed descriptions.]
RS.AN-5: Processes are established to receive, analyze and respond to vulnerabilities disclosed to the organization from internal and external sources (e.g. internal testing, security bulletins, or security researchers)
[csf.tools Note: Subcategories do not have detailed descriptions.]