RS.MA-04: Incidents are escalated or elevated as needed

Subcategory is new to this version of the framework and incorporates the following items from the previous version: RS.AN-2: The impact of the incident is understood, RS.CO-4: Coordination with stakeholders occurs consistent with response plans.


[ Note: Subcategories do not have detailed descriptions. However NIST has provided the following implementation examples.]

Implementation Examples

1st: 1st Party Risk

Ex1: Track and validate the status of all ongoing incidents

Ex2: Coordinate incident escalation or elevation with designated internal and external stakeholders