RESPOND (RS)¶
Actions regarding a detected cybersecurity incident are taken
Informative References
- CRI Profile v2.0: RS
- CSF v1.1: RS
- ISO/IEC 27001:2022: Mandatory Clause: None
- ISO/IEC 27001:2022: Annex A Controls: 5.26
- SCF: IRO-01
- SCF: IRO-02
- SCF: IRO-04
- SCF: IRO-07
- SCF: IRO-09
- SCF: IRO-10
Incident Management (RS.MA)¶
Responses to detected cybersecurity incidents are managed
Informative References
- CRI Profile v2.0: RS.MA
- CSF v1.1: RS.RP
- ISO/IEC 27001:2022: Mandatory Clause: None
- ISO/IEC 27001:2022: Annex A Controls: 5.24
- ISO/IEC 27001:2022: Annex A Controls: 5.25
- ISO/IEC 27001:2022: Annex A Controls: 5.26
- ISO/IEC 27001:2022: Annex A Controls: 5.27
- ISO/IEC 27001:2022: Annex A Controls: 5.28
- NICE Framework: IO-WRL-005
- NICE Framework: IO-WRL-006
- NICE Framework: IO-WRL-007
- NICE Framework: OG-WRL-007
- NICE Framework: OG-WRL-010
- NICE Framework: OG-WRL-015
- NICE Framework: PD-WRL-001
- NICE Framework: PD-WRL-002
- NICE Framework: PD-WRL-003
- NICE Framework: PD-WRL-004
- NICE Framework: PD-WRL-005
- NICE Framework: PD-WRL-006
- NICE Framework: PD-WRL-007
- SCF: IRO-02
- SCF: IRO-04
- SCF: IRO-07
- SP 800-171 Rev 3: 03.06.01
- SP 800-171 Rev 3: 03.06.02
- SP 800-171 Rev 3: 03.06.05
- SP 800-53 Rev 5.1.1: IR-04
- SP 800-53 Rev 5.1.1: IR-07
- SP 800-53 Rev 5.1.1: IR-08
- SP 800-53 Rev 5.1.1: IR-09
- SP 800-53 Rev 5.2.0: IR-04
- SP 800-53 Rev 5.2.0: IR-07
- SP 800-53 Rev 5.2.0: IR-08
- SP 800-53 Rev 5.2.0: IR-09
RS.MA-01¶
The incident response plan is executed in coordination with relevant third parties once an incident is declared
Implementation Examples
- Ex1: Detection technologies automatically report confirmed incidents
- Ex2: Request incident response assistance from the organization's incident response outsourcer
- Ex3: Designate an incident lead for each incident
- Ex4: Initiate execution of additional cybersecurity plans as needed to support incident response (for example, business continuity and disaster recovery)
Informative References
- AI-SOC: AI-SOC-12
- AI-SOC: AI-SOC-04
- CCMv4.0: BCR-07
- CCMv4.0: IVS-09
- CCMv4.0: SEF-01
- CCMv4.0: SEF-03
- CCMv4.0: SEF-07
- CIS Controls v8.0: 17.4
- CIS Controls v8.1: 17.4
- CRI Profile v2.0: RS.MA-01
- CRI Profile v2.0: RS.MA-01.01
- CSF v1.1: RS.RP-1
- CSF v1.1: RS.CO-4
- CoP: D1
- IRP: IRP-Sec-6
- ISO/IEC 27001:2022: Mandatory Clause: None
- ISO/IEC 27001:2022: Annex A Controls: 5.26
- ISO/IEC 27001:2022: Annex A Controls: 5.27
- ISO/IEC 27001:2022: Annex A Controls: 5.28
- ISO/IEC 27001:2022: Control 5.26
- NICE Framework: IO-WRL-005
- NICE Framework: IO-WRL-007
- NICE Framework: OG-WRL-007
- NICE Framework: OG-WRL-010
- NICE Framework: PD-WRL-001
- NICE Framework: PD-WRL-003
- NICE Framework: PD-WRL-004
- OWASP Top 10 LLM Applications: LLM01-2025
- OWASP Top 10 LLM Applications: LLM02-2025
- OWASP Top 10 LLM Applications: LLM04-2025
- PCI DSS: 12.10.1
- PCI DSS: 12.10.3
- PCI DSS: 12.10.2
- PCI DSS: 12.8.2
- SCF: IRO-02
- SCF: IRO-02.5
- SCF: IRO-04
- SCF: IRO-07
- SCF: IRO-10
- SP 800-171 Rev 3: 03.06.02
- SP 800-171 Rev 3: 03.06.05
- SP 800-171 Rev 3: 03.17.03
- SP 800-53 Rev 5.1.1: IR-06
- SP 800-53 Rev 5.1.1: IR-07
- SP 800-53 Rev 5.1.1: IR-08
- SP 800-53 Rev 5.1.1: SR-03
- SP 800-53 Rev 5.1.1: SR-08
- SP 800-53 Rev 5.2.0: IR-06
- SP 800-53 Rev 5.2.0: IR-07
- SP 800-53 Rev 5.2.0: IR-08
- SP 800-53 Rev 5.2.0: SR-03
- SP 800-53 Rev 5.2.0: SR-08
RS.MA-02¶
Incident reports are triaged and validated
Implementation Examples
- Ex1: Preliminarily review incident reports to confirm that they are cybersecurity-related and necessitate incident response activities
- Ex2: Apply criteria to estimate the severity of an incident
Informative References
- AI-SOC: AI-SOC-04
- AI-SOC: AI-SOC-06
- CCMv4.0: SEF-06
- CRI Profile v2.0: RS.MA-02
- CRI Profile v2.0: RS.MA-02.01
- CSF v1.1: RS.AN-1
- CSF v1.1: RS.AN-2
- CoP: D3
- Guardian-SDK: GS-PF-04
- ISO/IEC 27001:2022: Mandatory Clause: None
- ISO/IEC 27001:2022: Annex A Controls: 5.24
- ISO/IEC 27001:2022: Annex A Controls: 5.26
- ISO/IEC 27001:2022: Annex A Controls: 5.27
- ISO/IEC 27001:2022: Annex A Controls: 5.28
- ISO/IEC 27001:2022: Annex A Controls: 6.8
- NICE Framework: IO-WRL-005
- NICE Framework: IO-WRL-006
- NICE Framework: IO-WRL-007
- NICE Framework: PD-WRL-001
- NICE Framework: PD-WRL-002
- NICE Framework: PD-WRL-003
- NICE Framework: PD-WRL-005
- OWASP Top 10 LLM Applications: LLM01-2025
- OWASP Top 10 LLM Applications: LLM02-2025
- PCI DSS: 10.4.1
- PCI DSS: 10.2.1
- PCI DSS: 12.10.1
- PCI DSS: 12.10.4
- SCF: IRO-02
- SCF: IRO-04
- SDOS: SDOS-AU-01
- SDOS: SDOS-RS-01
- SP 800-171 Rev 3: 03.06.01
- SP 800-171 Rev 3: 03.06.02
- SP 800-53 Rev 5.1.1: IR-04
- SP 800-53 Rev 5.1.1: IR-05
- SP 800-53 Rev 5.1.1: IR-06
- SP 800-53 Rev 5.2.0: IR-04
- SP 800-53 Rev 5.2.0: IR-05
- SP 800-53 Rev 5.2.0: IR-06
RS.MA-03¶
Incidents are categorized and prioritized
Implementation Examples
- Ex1: Further review and categorize incidents based on the type of incident (e.g., data breach, ransomware, DDoS, account compromise)
- Ex2: Prioritize incidents based on their scope, likely impact, and time-critical nature
- Ex3: Select incident response strategies for active incidents by balancing the need to quickly recover from an incident with the need to observe the attacker or conduct a more thorough investigation
Informative References
- CCMv4.0: SEF-02
- CCMv4.0: SEF-06
- CRI Profile v2.0: RS.MA-03
- CRI Profile v2.0: RS.MA-03.01
- CSF v1.1: RS.AN-4
- CSF v1.1: RS.AN-2
- Guardian-SDK: GS-PF-04
- ISO/IEC 27001:2022: Mandatory Clause: None
- ISO/IEC 27001:2022: Annex A Controls: 5.25
- NICE Framework: IO-WRL-005
- NICE Framework: IO-WRL-006
- NICE Framework: IO-WRL-007
- NICE Framework: PD-WRL-001
- NICE Framework: PD-WRL-002
- NICE Framework: PD-WRL-003
- NICE Framework: PD-WRL-006
- PCI DSS: 12.10.1
- PCI DSS: 10.4.1
- PCI DSS: 12.10.2
- PCI DSS: 12.10.6
- SCF: IRO-02.4
- SDOS: SDOS-AU-01
- SDOS: SDOS-RM-01
- SP 800-171 Rev 3: 03.06.01
- SP 800-171 Rev 3: 03.06.02
- SP 800-53 Rev 5.1.1: IR-04
- SP 800-53 Rev 5.1.1: IR-05
- SP 800-53 Rev 5.1.1: IR-06
- SP 800-53 Rev 5.2.0: IR-04
- SP 800-53 Rev 5.2.0: IR-05
- SP 800-53 Rev 5.2.0: IR-06
RS.MA-04¶
Incidents are escalated or elevated as needed
Implementation Examples
- Ex1: Track and validate the status of all ongoing incidents
- Ex2: Coordinate incident escalation or elevation with designated internal and external stakeholders
Informative References
- CCMv4.0: SEF-02
- CRI Profile v2.0: RS.MA-04
- CRI Profile v2.0: RS.MA-04.01
- CSF v1.1: RS.AN-2
- CSF v1.1: RS.CO-4
- ISO/IEC 27001:2022: Mandatory Clause: None
- ISO/IEC 27001:2022: Annex A Controls: 5.26
- NICE Framework: IO-WRL-005
- NICE Framework: IO-WRL-006
- NICE Framework: IO-WRL-007
- NICE Framework: PD-WRL-001
- NICE Framework: PD-WRL-003
- NICE Framework: PD-WRL-007
- PCI DSS: 12.10.3
- PCI DSS: 12.10.1
- PCI DSS: 12.10.2
- SCF: IRO-02
- SCF: IRO-04
- SCF: IRO-07
- SDOS: SDOS-DE-01
- SDOS: SDOS-RM-01
- SP 800-171 Rev 3: 03.06.01
- SP 800-171 Rev 3: 03.06.02
- SP 800-53 Rev 5.1.1: IR-04
- SP 800-53 Rev 5.1.1: IR-05
- SP 800-53 Rev 5.1.1: IR-06
- SP 800-53 Rev 5.1.1: IR-07
- SP 800-53 Rev 5.2.0: IR-04
- SP 800-53 Rev 5.2.0: IR-05
- SP 800-53 Rev 5.2.0: IR-06
- SP 800-53 Rev 5.2.0: IR-07
RS.MA-05¶
The criteria for initiating incident recovery are applied
Implementation Examples
- Ex1: Apply incident recovery criteria to known and assumed characteristics of the incident to determine whether incident recovery processes should be initiated
- Ex2: Take the possible operational disruption of incident recovery activities into account
Informative References
- AI-SOC: AI-SOC-12
- AI-SOC: AI-SOC-04
- CCMv4.0: SEF-02
- CIS Controls v8.0: 17.9
- CIS Controls v8.1: 17.9
- CRI Profile v2.0: RS.MA-05
- CRI Profile v2.0: RS.MA-05.01
- ISO/IEC 27001:2022: Mandatory Clause: None
- ISO/IEC 27001:2022: Annex A Controls: 5.25
- NICE Framework: IO-WRL-005
- NICE Framework: IO-WRL-007
- NICE Framework: OG-WRL-007
- NICE Framework: OG-WRL-010
- NICE Framework: OG-WRL-015
- NICE Framework: PD-WRL-001
- NICE Framework: PD-WRL-003
- OWASP Top 10 LLM Applications: LLM04-2025
- PCI DSS: 12.10.1
- PCI DSS: 12.10.2
- PCI DSS: 12.10.6
- SCF: BCD-01
- SDOS: SDOS-AU-01
- SDOS: SDOS-RM-01
- SDOS: SDOS-RS-01
- SP 800-171 Rev 3: 03.06.01
- SP 800-171 Rev 3: 03.06.05
- SP 800-53 Rev 5.1.1: IR-04
- SP 800-53 Rev 5.1.1: IR-08
- SP 800-53 Rev 5.2.0: IR-04
- SP 800-53 Rev 5.2.0: IR-08
Incident Analysis (RS.AN)¶
Investigations are conducted to ensure effective response and support forensics and recovery activities
Informative References
- CRI Profile v2.0: RS.AN
- CSF v1.1: RS.AN
- ISO/IEC 27001:2022: Mandatory Clause: None
- ISO/IEC 27001:2022: Annex A Controls: 5.26
- ISO/IEC 27001:2022: Annex A Controls: 5.28
- NICE Framework: IO-WRL-001
- NICE Framework: IO-WRL-002
- NICE Framework: IO-WRL-003
- NICE Framework: IO-WRL-006
- NICE Framework: OG-WRL-012
- NICE Framework: PD-WRL-002
- NICE Framework: PD-WRL-003
- NICE Framework: PD-WRL-004
- SCF: IRO-02
- SCF: IRO-08
- SP-800-37 Rev 2: RMF Monitor Step: TASK M-3 Ongoing Risk Response
RS.AN-01¶
[Withdrawn: Incorporated into RS.MA-02]
RS.AN-02¶
[Withdrawn: Incorporated into RS.MA-02, RS.MA-03, RS.MA-04]
RS.AN-03¶
Analysis is performed to establish what has taken place during an incident and the root cause of the incident
Implementation Examples
- Ex1: Determine the sequence of events that occurred during the incident and which assets and resources were involved in each event
- Ex2: Attempt to determine what vulnerabilities, threats, and threat actors were directly or indirectly involved in the incident
- Ex3: Analyze the incident to find the underlying, systemic root causes
- Ex4: Check any cyber deception technology for additional information on attacker behavior
Informative References
- AI-SOC: AI-SOC-23
- AI-SOC: AI-SOC-13
- CCMv4.0: SEF-06
- CIS Controls v8.0: 17.8
- CIS Controls v8.1: 17.8
- CRI Profile v2.0: RS.AN-03
- CRI Profile v2.0: RS.AN-03.01
- CSF v1.1: RS.AN-3
- CoP: D4
- ISO/IEC 27001:2022: Mandatory Clause: None
- ISO/IEC 27001:2022: Annex A Controls: 5.25
- ISO/IEC 27001:2022: Annex A Controls: 5.27
- NICE Framework: IO-WRL-001
- NICE Framework: IO-WRL-003
- NICE Framework: IO-WRL-006
- NICE Framework: OG-WRL-012
- NICE Framework: PD-WRL-002
- NICE Framework: PD-WRL-003
- NICE Framework: PD-WRL-004
- OWASP Top 10 LLM Applications: LLM01-2025
- OWASP Top 10 LLM Applications: LLM04-2025
- OWASP Top 10 LLM Applications: LLM05-2025
- PCI DSS: 10.2.1
- PCI DSS: 10.4.1
- PCI DSS: 6.3.1
- PCI DSS: 10.2.2
- SCF: IRO-13
- SDOS: SDOS-AU-01
- SDOS: SDOS-AU-02
- SDOS: SDOS-DE-02
- SDOS: SDOS-RS-01
- SP 800-171 Rev 3: 03.03.06
- SP 800-171 Rev 3: 03.06.01
- SP 800-53 Rev 5.1.1: AU-07
- SP 800-53 Rev 5.1.1: IR-04
- SP 800-53 Rev 5.2.0: AU-07
- SP 800-53 Rev 5.2.0: IR-04
- SP 800-53 Rev 5.2.0: SI-02(07)
RS.AN-04¶
[Withdrawn: Moved to RS.MA-03]
RS.AN-05¶
[Withdrawn: Moved to ID.RA-08]
RS.AN-06¶
Actions performed during an investigation are recorded, and the records' integrity and provenance are preserved
Implementation Examples
- Ex1: Require each incident responder and others (e.g., system administrators, cybersecurity engineers) who perform incident response tasks to record their actions and make the record immutable
- Ex2: Require the incident lead to document the incident in detail and be responsible for preserving the integrity of the documentation and the sources of all information being reported
Informative References
- CRI Profile v2.0: RS.AN-06
- CRI Profile v2.0: RS.AN-06.01
- CSF v1.1: RS.AN-3
- Guardian-SDK: GS-CF-02
- ISO/IEC 27001:2022: Mandatory Clause: None
- ISO/IEC 27001:2022: Annex A Controls: 5.28
- NICE Framework: IO-WRL-001
- NICE Framework: IO-WRL-002
- NICE Framework: IO-WRL-003
- NICE Framework: IO-WRL-006
- NICE Framework: PD-WRL-002
- NICE Framework: PD-WRL-003
- NICE Framework: PD-WRL-004
- PCI DSS: 10.3.2
- PCI DSS: 10.3.1
- PCI DSS: 10.3.3
- PCI DSS: 10.3.4
- PCI DSS: 10.6.1
- PCI DSS: 10.5.1
- SCF: IRO-02
- SCF: IRO-08
- SCF: IRO-09
- SDOS: SDOS-AU-01
- SDOS: SDOS-AU-03
- SP 800-171 Rev 3: 03.03.06
- SP 800-171 Rev 3: 03.06.01
- SP 800-171 Rev 3: 03.06.02
- SP 800-53 Rev 5.1.1: AU-07
- SP 800-53 Rev 5.1.1: IR-04
- SP 800-53 Rev 5.1.1: IR-06
- SP 800-53 Rev 5.2.0: AU-07
- SP 800-53 Rev 5.2.0: IR-04
- SP 800-53 Rev 5.2.0: IR-06
RS.AN-07¶
Incident data and metadata are collected, and their integrity and provenance are preserved
Implementation Examples
- Ex1: Collect, preserve, and safeguard the integrity of all pertinent incident data and metadata (e.g., data source, date/time of collection) based on evidence preservation and chain-of-custody procedures
Informative References
- AI-SOC: AI-SOC-23
- AI-SOC: AI-SOC-22
- CRI Profile v2.0: RS.AN-07
- CRI Profile v2.0: RS.AN-07.01
- ISO/IEC 27001:2022: Mandatory Clause: None
- ISO/IEC 27001:2022: Annex A Controls: 5.28
- ISO/IEC 27001:2022: Control 5.28
- NICE Framework: IO-WRL-001
- NICE Framework: IO-WRL-002
- NICE Framework: IO-WRL-003
- NICE Framework: IO-WRL-006
- NICE Framework: PD-WRL-002
- NICE Framework: PD-WRL-003
- NICE Framework: PD-WRL-004
- OWASP Top 10 LLM Applications: LLM02-2025
- OWASP Top 10 LLM Applications: LLM04-2025
- PCI DSS: 10.2.1
- PCI DSS: 10.3.2
- PCI DSS: 10.3.3
- PCI DSS: 10.6.1
- PCI DSS: 10.2.2
- SCF: IRO-08
- SDOS: SDOS-AU-01
- SDOS: SDOS-AU-03
- SP 800-171 Rev 3: 03.03.06
- SP 800-171 Rev 3: 03.06.01
- SP 800-171 Rev 3: 03.06.02
- SP 800-53 Rev 5.1.1: AU-07
- SP 800-53 Rev 5.1.1: IR-04
- SP 800-53 Rev 5.1.1: IR-06
- SP 800-53 Rev 5.2.0: AU-07
- SP 800-53 Rev 5.2.0: IR-04
- SP 800-53 Rev 5.2.0: IR-06
- SP 800-81r3: 2.1.3
RS.AN-08¶
An incident's magnitude is estimated and validated
Implementation Examples
- Ex1: Review other potential targets of the incident to search for indicators of compromise and evidence of persistence
- Ex2: Automatically run tools on targets to look for indicators of compromise and evidence of persistence
Informative References
- AI-SOC: AI-SOC-06
- AI-SOC: AI-SOC-17
- CRI Profile v2.0: RS.AN-08
- CRI Profile v2.0: RS.AN-08.01
- ISO/IEC 27001:2022: Mandatory Clause: None
- ISO/IEC 27001:2022: Annex A Controls: 5.25
- NICE Framework: IO-WRL-001
- NICE Framework: IO-WRL-003
- NICE Framework: IO-WRL-006
- NICE Framework: OG-WRL-012
- NICE Framework: PD-WRL-003
- NICE Framework: PD-WRL-004
- OWASP Top 10 LLM Applications: LLM02-2025
- OWASP Top 10 LLM Applications: LLM04-2025
- PCI DSS: 10.4.1
- PCI DSS: 1.2.3
- PCI DSS: 1.2.4
- PCI DSS: 12.5.1
- SCF: IRO-02.4
- SDOS: SDOS-AU-01
- SDOS: SDOS-RM-01
- SP 800-171 Rev 3: 03.06.01
- SP 800-171 Rev 3: 03.06.05
- SP 800-171 Rev 3: 03.11.01
- SP 800-171 Rev 3: 03.11.04
- SP 800-53 Rev 5.1.1: IR-04
- SP 800-53 Rev 5.1.1: IR-08
- SP 800-53 Rev 5.1.1: RA-03
- SP 800-53 Rev 5.1.1: RA-07
- SP 800-53 Rev 5.2.0: IR-04
- SP 800-53 Rev 5.2.0: IR-08
- SP 800-53 Rev 5.2.0: RA-03
- SP 800-53 Rev 5.2.0: RA-07
Incident Response Reporting and Communication (RS.CO)¶
Response activities are coordinated with internal and external stakeholders as required by laws, regulations, or policies
Informative References
- CRI Profile v2.0: RS.CO
- CSF v1.1: RS.CO
- ISO/IEC 27001:2022: Mandatory Clause: None
- ISO/IEC 27001:2022: Annex A Controls: 5.26
- NICE Framework: OG-WRL-006
- NICE Framework: OG-WRL-007
- NICE Framework: OG-WRL-008
- NICE Framework: OG-WRL-010
- NICE Framework: OG-WRL-015
- NICE Framework: PD-WRL-003
- SCF: IRO-02
- SCF: IRO-02.5
- SCF: IRO-06.1
- SCF: IRO-09
- SCF: IRO-10
- SCF: IRO-10.4
- SP-800-37 Rev 2: RMF Monitor Step: TASK M-3 Ongoing Risk Response
RS.CO-01¶
[Withdrawn: Incorporated into PR.AT-01]
RS.CO-02¶
Internal and external stakeholders are notified of incidents
Implementation Examples
- Ex1: Follow the organization's breach notification procedures after discovering a data breach incident, including notifying affected customers
- Ex2: Notify business partners and customers of incidents in accordance with contractual requirements
- Ex3: Notify law enforcement agencies and regulatory bodies of incidents based on criteria in the incident response plan and management approval
Informative References
- AI-SOC: AI-SOC-30
- AI-SOC: AI-SOC-12
- CCMv4.0: DSP-18
- CCMv4.0: SEF-02
- CCMv4.0: SEF-07
- CCMv4.0: SEF-08
- CIS Controls v8.0: 17.2
- CIS Controls v8.1: 17.2
- CRI Profile v2.0: RS.CO-02
- CRI Profile v2.0: RS.CO-02.01
- CRI Profile v2.0: RS.CO-02.02
- CRI Profile v2.0: RS.CO-02.03
- CSF v1.1: RS.CO-2
- CSF v1.1: RS.CO-3
- Guardian-SDK: GS-CF-02
- ISO/IEC 27001:2022: Mandatory Clause: 7.4
- ISO/IEC 27001:2022: Annex A Controls: 5.26
- NICE Framework: OG-WRL-006
- NICE Framework: OG-WRL-007
- NICE Framework: OG-WRL-008
- NICE Framework: OG-WRL-010
- NICE Framework: OG-WRL-015
- NICE Framework: PD-WRL-003
- OWASP Top 10 LLM Applications: LLM02-2025
- PCI DSS: 12.10.1
- PCI DSS: 12.10.3
- PCI DSS: 12.8.2
- PCI DSS: 12.8.5
- SCF: IRO-02
- SCF: IRO-10
- SCF: IRO-10.4
- SDOS: SDOS-AU-03
- SP 800-171 Rev 3: 03.06.01
- SP 800-171 Rev 3: 03.06.02
- SP 800-171 Rev 3: 03.17.03
- SP 800-53 Rev 5.1.1: IR-04
- SP 800-53 Rev 5.1.1: IR-06
- SP 800-53 Rev 5.1.1: IR-07
- SP 800-53 Rev 5.1.1: SR-03
- SP 800-53 Rev 5.1.1: SR-08
- SP 800-53 Rev 5.2.0: IR-04
- SP 800-53 Rev 5.2.0: IR-06
- SP 800-53 Rev 5.2.0: IR-07
- SP 800-53 Rev 5.2.0: SR-03
- SP 800-53 Rev 5.2.0: SR-08
RS.CO-03¶
Information is shared with designated internal and external stakeholders
Implementation Examples
- Ex1: Securely share information consistent with response plans and information sharing agreements
- Ex2: Voluntarily share information about an attacker's observed TTPs, with all sensitive data removed, with an Information Sharing and Analysis Center (ISAC)
- Ex3: Notify HR when malicious insider activity occurs
- Ex4: Regularly update senior leadership on the status of major incidents
- Ex5: Follow the rules and protocols defined in contracts for incident information sharing between the organization and its suppliers
- Ex6: Coordinate crisis communication methods between the organization and its critical suppliers
Informative References
- AI-SOC: AI-SOC-30
- AI-SOC: AI-SOC-12
- CCMv4.0: BCR-07
- CCMv4.0: DSP-18
- CCMv4.0: SEF-07
- CCMv4.0: SEF-08
- CIS Controls v8.0: 17.2
- CIS Controls v8.1: 17.2
- CRI Profile v2.0: RS.CO-03
- CRI Profile v2.0: RS.CO-03.01
- CRI Profile v2.0: RS.CO-03.02
- CSF v1.1: RS.CO-3
- CSF v1.1: RS.CO-5
- ISO/IEC 27001:2022: Mandatory Clause: 7.4
- ISO/IEC 27001:2022: Annex A Controls: 5.26
- NICE Framework: OG-WRL-006
- NICE Framework: OG-WRL-007
- NICE Framework: OG-WRL-008
- NICE Framework: OG-WRL-010
- NICE Framework: OG-WRL-015
- NICE Framework: PD-WRL-003
- OWASP Top 10 LLM Applications: LLM02-2025
- OWASP Top 10 LLM Applications: LLM03-2025
- PCI DSS: 12.10.1
- PCI DSS: 12.8.2
- PCI DSS: 12.8.4
- PCI DSS: 12.10.6
- SCF: IRO-02
- SCF: IRO-10
- SCF: IRO-10.4
- SDOS: SDOS-AU-03
- SP 800-171 Rev 3: 03.06.01
- SP 800-171 Rev 3: 03.06.02
- SP 800-171 Rev 3: 03.17.03
- SP 800-53 Rev 5.1.1: IR-04
- SP 800-53 Rev 5.1.1: IR-06
- SP 800-53 Rev 5.1.1: IR-07
- SP 800-53 Rev 5.1.1: SR-03
- SP 800-53 Rev 5.1.1: SR-08
- SP 800-53 Rev 5.2.0: IR-04
- SP 800-53 Rev 5.2.0: IR-06
- SP 800-53 Rev 5.2.0: IR-07
- SP 800-53 Rev 5.2.0: SR-03
- SP 800-53 Rev 5.2.0: SR-08
- SP 800-81r3: 2.3.3
- SP 800-81r3: 3.4.2
RS.CO-04¶
[Withdrawn: Incorporated into RS.MA-01, RS.MA-04]
RS.CO-05¶
[Withdrawn: Incorporated into RS.CO-03]
Incident Mitigation (RS.MI)¶
Activities are performed to prevent expansion of an event and mitigate its effects
Informative References
- CRI Profile v2.0: RS.MI
- CSF v1.1: RS.MI
- ISO/IEC 27001:2022: Mandatory Clause: None
- ISO/IEC 27001:2022: Annex A Controls: 5.26
- NICE Framework: DD-WRL-001
- NICE Framework: IO-WRL-005
- NICE Framework: IO-WRL-007
- NICE Framework: OG-WRL-014
- NICE Framework: PD-WRL-003
- NICE Framework: PD-WRL-004
- SCF: IRO-01
- SCF: IRO-02
- SCF: IRO-04
- SP-800-37 Rev 2: RMF Monitor Step: TASK M-3 Ongoing Risk Response
RS.MI-01¶
Incidents are contained
Implementation Examples
- Ex1: Cybersecurity technologies (e.g., antivirus software) and cybersecurity features of other technologies (e.g., operating systems, network infrastructure devices) automatically perform containment actions
- Ex2: Allow incident responders to manually select and perform containment actions
- Ex3: Allow a third party (e.g., internet service provider, managed security service provider) to perform containment actions on behalf of the organization
- Ex4: Automatically transfer compromised endpoints to a remediation virtual local area network (VLAN)
Informative References
- AI-SOC: AI-SOC-07
- AI-SOC: AI-SOC-24
- BXAIOS: Chapter 7 - Deploy the Governor
- CCMv4.0: CEK-19
- CCMv4.0: CEK-20
- CCMv4.0: IVS-09
- CCMv4.0: SEF-02
- CCMv4.0: UEM-09
- CRI Profile v2.0: RS.MI-01
- CRI Profile v2.0: RS.MI-01.01
- CSF v1.1: RS.MI-1
- Guardian-SDK: GS-PF-01
- Guardian-SDK: GS-PO-01
- Guardian-SDK: GS-AG-01
- IRP: IRP-Sec-5
- ISO/IEC 27001:2022: Mandatory Clause: None
- ISO/IEC 27001:2022: Annex A Controls: 5.26
- NICE Framework: DD-WRL-001
- NICE Framework: IO-WRL-005
- NICE Framework: IO-WRL-007
- NICE Framework: OG-WRL-014
- NICE Framework: PD-WRL-003
- NICE Framework: PD-WRL-004
- OWASP Top 10 LLM Applications: LLM01-2025
- OWASP Top 10 LLM Applications: LLM04-2025
- OWASP Top 10 LLM Applications: LLM06-2025
- OWASP Top 10 LLM Applications: LLM10-2025
- PCI DSS: 12.10.1
- PCI DSS: 5.2.1
- PCI DSS: 5.2.2
- PCI DSS: 5.3.2
- SCF: IRO-02
- SDOS: SDOS-EN-01
- SDOS: SDOS-EN-03
- SDOS: SDOS-IN-02
- SP 800-171 Rev 3: 03.06.01
- SP 800-53 Rev 5.1.1: IR-04
- SP 800-53 Rev 5.2.0: IR-04
- SP 800-81r3: 3.6.3
RS.MI-02¶
Incidents are eradicated
Implementation Examples
- Ex1: Cybersecurity technologies and cybersecurity features of other technologies (e.g., operating systems, network infrastructure devices) automatically perform eradication actions
- Ex2: Allow incident responders to manually select and perform eradication actions
- Ex3: Allow a third party (e.g., managed security service provider) to perform eradication actions on behalf of the organization
Informative References
- AI-SOC: AI-SOC-24
- AI-SOC: AI-SOC-08
- CCMv4.0: CEK-19
- CCMv4.0: IVS-09
- CCMv4.0: SEF-02
- CCMv4.0: SEF-06
- CRI Profile v2.0: RS.MI-02
- CRI Profile v2.0: RS.MI-02.01
- CSF v1.1: RS.MI-2
- ISO/IEC 27001:2022: Mandatory Clause: None
- ISO/IEC 27001:2022: Annex A Controls: 5.26
- NICE Framework: DD-WRL-001
- NICE Framework: IO-WRL-005
- NICE Framework: IO-WRL-007
- NICE Framework: OG-WRL-014
- NICE Framework: PD-WRL-003
- NICE Framework: PD-WRL-004
- OWASP Top 10 LLM Applications: LLM01-2025
- OWASP Top 10 LLM Applications: LLM03-2025
- OWASP Top 10 LLM Applications: LLM04-2025
- PCI DSS: 12.10.1
- PCI DSS: 6.3.3
- PCI DSS: 5.2.2
- PCI DSS: 6.2.3
- PCI DSS: 2.2.1
- SCF: IRO-02
- SDOS: SDOS-GV-01
- SDOS: SDOS-IA-02
- SP 800-171 Rev 3: 03.06.01
- SP 800-53 Rev 5.1.1: IR-04
- SP 800-53 Rev 5.2.0: IR-04
RS.MI-03¶
[Withdrawn: Incorporated into ID.RA-06]
Response Planning (RS.RP)¶
[Withdrawn: Incorporated into RS.MA]
RS.RP-01¶
[Withdrawn: Incorporated into RS.MA-01]
Improvements (RS.IM)¶
[Withdrawn: Incorporated into ID.IM]
RS.IM-01¶
[Withdrawn: Incorporated into ID.IM-03, ID.IM-04]
RS.IM-02¶
[Withdrawn: Incorporated into ID.IM-03]