IR-4(5): Automatic Disabling of System
Control Family:
Parent Control:
CSF v1.1 References:
Baselines:
(Not part of any baseline)
Previous Version:
- NIST Special Publication 800-53 Revision 4:
- IR-4(5): Automatic Disabling Of Information System
Control Statement
Implement a configurable capability to automatically disable the system if [Assignment: organization-defined security violations] are detected.
Supplemental Guidance
Organizations consider whether the capability to automatically disable the system conflicts with continuity of operations requirements specified as part of CP-2 or IR-4(3). Security violations include cyber-attacks that have compromised the integrity of the system or exfiltrated organizational information and serious errors in software programs that could adversely impact organizational missions or functions or jeopardize the safety of individuals.