Implement an incident handling capability for incidents that is consistent with the incident response plan and includes preparation, detection and analysis, containment, eradication, and recovery; Coordinate incident handling activities with contingency planning activities; Incorporate lessons learned from ongoing incident handling activities into incident response procedures, training, and testing, and implement the resulting changes accordingly; and Ensure the rigor, intensity, scope, and results of incident handling activities are comparable and predictable across the organization.
family IR
framework nist-800-53
Equivalent controls in other frameworks click any to see its ATT&CK technique mappings
Support the incident handling process using {{ insert: param, ir-04.01_odp }}.
family IR
framework nist-800-53
Coordinate incident handling activities involving supply chain events with other organizations involved in the supply chain.
family IR
framework nist-800-53
Establish and maintain an integrated incident response team that can be deployed to any location identified by the organization in {{ insert: param, ir-04.11_odp }}.
family IR
framework nist-800-53
Analyze malicious code and/or other residual artifacts remaining in the system after the incident.
family IR
framework nist-800-53
Analyze anomalous or suspected adversarial behavior in or related to {{ insert: param, ir-04.13_odp }}.
family IR
framework nist-800-53
Establish and maintain a security operations center.
family IR
framework nist-800-53
Manage public relations associated with an incident; and Employ measures to repair the reputation of the organization.
family IR
framework nist-800-53
Include the following types of dynamic reconfiguration for {{ insert: param, ir-04.02_odp.02 }} as part of the incident response capability: {{ insert: param, ir-04.02_odp.01 }}.
family IR
framework nist-800-53
Identify {{ insert: param, ir-04.03_odp.01 }} and take the following actions in response to those incidents to ensure continuation of organizational mission and business functions: {{ insert: param, ir-04.03_odp.02 }}.
family IR
framework nist-800-53
Correlate incident information and individual incident responses to achieve an organization-wide perspective on incident awareness and response.
family IR
framework nist-800-53
Implement a configurable capability to automatically disable the system if {{ insert: param, ir-04.05_odp }} are detected.
family IR
framework nist-800-53
Implement an incident handling capability for incidents involving insider threats.
family IR
framework nist-800-53
Coordinate an incident handling capability for insider threats that includes the following organizational entities {{ insert: param, ir-04.07_odp }}.
family IR
framework nist-800-53
Coordinate with {{ insert: param, ir-04.08_odp.01 }} to correlate and share {{ insert: param, ir-04.08_odp.02 }} to achieve a cross-organization perspective on incident awareness and more effective incident responses.
family IR
framework nist-800-53
Employ {{ insert: param, ir-04.09_odp }} to respond to incidents.
family IR
framework nist-800-53