IR-6: Incident Reporting

Control Family:

Incident Response

CSF v1.1 References:

PF v1.0 References:

Baselines:

  • Low
    • IR-6
  • Moderate
  • High
  • Privacy
    • IR-6
  • OT Low (SP 800-82r3)
    • IR-6
  • OT Moderate (SP 800-82r3)
  • OT High (SP 800-82r3)

Previous Version:

Control Statement

  1. Require personnel to report suspected incidents to the organizational incident response capability within [Assignment: organization-defined time period] ; and
  2. Report incident information to [Assignment: organization-defined authorities].

Supplemental Guidance

The types of incidents reported, the content and timeliness of the reports, and the designated reporting authorities reflect applicable laws, executive orders, directives, regulations, policies, standards, and guidelines. Incident information can inform risk assessments, control effectiveness assessments, security requirements for acquisitions, and selection criteria for technology products.

OT Discussion

The organization should report incidents on a timely basis. CISA collaborates with international and private-sector computer emergency response teams (CERTs) to share control systems-related security incidents and mitigation measures.

Control Enhancements

IR-6(1): Automated Reporting

Baseline(s):

  • Moderate
  • High
  • OT Moderate (SP 800-82r3)
  • OT High (SP 800-82r3)

Report incidents using [Assignment: organization-defined automated mechanisms].

IR-6(3): Supply Chain Coordination

Baseline(s):

  • Moderate
  • High
  • OT Moderate (SP 800-82r3)
  • OT High (SP 800-82r3)

Provide incident information to the provider of the product or service and other organizations involved in the supply chain or supply chain governance for systems or system components related to the incident.