RS.MA-01: The incident response plan is executed in coordination with relevant third parties once an incident is declared
Subcategory is new to this version of the framework and incorporates the following items from the previous version: RS.CO-4: Coordination with stakeholders occurs consistent with response plans, RS.RP-1: Response plan is executed during or after an incident.
Description
[csf.tools Note: Subcategories do not have detailed descriptions. However NIST has provided the following implementation examples.]
Implementation Examples
Ex1: Detection technologies automatically report confirmed incidents
Ex2: Request incident response assistance from the organization's incident response outsourcer
Ex3: Designate an incident lead for each incident
Ex4: Initiate execution of additional cybersecurity plans as needed to support incident response (for example, business continuity and disaster recovery)
3rd: 3rd Party Risk
Related Controls
NIST Special Publication 800-53 Revision 5.2.0
IR-4: Incident Handling
Implement an incident handling capability for incidents that is consistent with the incident response plan and includes preparation, detection and analysis, containment, eradication, and recovery; Coordinate incident handling activities with contingency planning activities; Incorporate lessons learned from ongoing incident handling activities into incident response procedures, training, and testing, and implement the resulting changes accordingly; and…
IR-6: Incident Reporting
Require personnel to report suspected incidents to the organizational incident response capability within [Assignment: organization-defined time period] ; and Report incident information to [Assignment: organization-defined authorities].
IR-7: Incident Response Assistance
Provide an incident response support resource, integral to the organizational incident response capability, that offers advice and assistance to users of the system for the handling and reporting of incidents.
IR-8: Incident Response Plan
Develop an incident response plan that: Provides the organization with a roadmap for implementing its incident response capability; Describes the structure and organization of the incident response capability; Provides a high-level approach for how the incident response capability fits into the overall organization; Meets the unique requirements of the organization, which relate to mission, size,…
IR-9: Information Spillage Response
Respond to information spills by: Assigning [Assignment: organization-defined personnel or roles] with responsibility for responding to information spills; Identifying the specific information involved in the system contamination; Alerting [Assignment: organization-defined personnel or roles] of the information spill using a method of communication not associated with the spill; Isolating the contaminated system or system component; Eradicating…
SR-3: Supply Chain Controls and Processes
Establish a process or processes to identify and address weaknesses or deficiencies in the supply chain elements and processes of [Assignment: organization-defined system or system component] in coordination with [Assignment: organization-defined supply chain personnel]; Employ the following controls to protect against supply chain risks to the system, system component, or system service and to limit…
SR-8: Notification Agreements
Establish agreements and procedures with entities involved in the supply chain for the system, system component, or system service for the [Assignment (one or more): notification of supply chain compromises, [Assignment: organization-defined results of assessments or audits] ].
NIST SP 800-171 Revision 3.0
03.06.01: Incident Handling
Implement an incident-handling capability that is consistent with the incident response plan and includes preparation, detection and analysis, containment, eradication, and recovery.
03.06.02: Incident Monitoring, Reporting, and Response Assistance
Track and document system security incidents. Report suspected incidents to the organizational incident response capability within [Assignment: organization-defined time period]. Report incident information to [Assignment: organization-defined authorities]. Provide an incident response support resource that offers advice and assistance to system users on handling and reporting incidents.
03.06.05: Incident Response Plan
Develop an incident response plan that: Provides the organization with a roadmap for implementing its incident response capability, Describes the structure and organization of the incident response capability, Provides a high-level approach for how the incident response capability fits into the overall organization, Defines reportable incidents, Addresses the sharing of incident information, and Designates responsibilities…
03.17.03: Supply Chain Requirements and Processes
Establish a process for identifying and addressing weaknesses or deficiencies in the supply chain elements and processes. Enforce the following security requirements to protect against supply chain risks to the system, system components, or system services and to limit the harm or consequences from supply chain-related events: [Assignment: organization-defined security requirements].
Cloud Controls Matrix v4.0
BCR-07: Communication
Establish communication with stakeholders and participants in the course of business continuity and resilience procedures.
IVS-09: Network Defense
Define, implement and evaluate processes, procedures and defense-in-depth techniques for protection, detection, and timely response to network-based attacks.
SEF-01: Security Incident Management Policy and Procedures
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for Security Incident Management, E-Discovery, and Cloud Forensics. Review and update the policies and procedures at least annually.
SEF-03: Incident Response Plans
Establish, document, approve, communicate, apply, evaluate and maintain a security incident response plan, which includes but is not limited to: relevant internal departments, impacted CSCs, and other business critical relationships (such as supply-chain) that may be impacted.
SEF-07: Security Breach Notification
Define and implement, processes, procedures and technical measures for security breach notifications. Report security breaches and assumed security breaches including any relevant supply chain breaches, as per applicable SLAs, laws and regulations.
Critical Security Controls Version 8.1
17.4: Establish and Maintain an Incident Response Process
Establish and maintain an incident response process that addresses roles and responsibilities, compliance requirements, and a communication plan. Review annually, or when significant enterprise changes occur that could impact this Safeguard.