IR-06 Incident Reporting

Incident Response

Low Moderate High Privacy

Description

The organization promptly reports incident information to appropriate authorities.\n

Supplemental Guidance

The types of incident information reported, the content and timeliness of the reports, and the list of designated reporting authorities or organizations are consistent with applicable laws, Executive Orders, directives, policies, regulations, standards, and guidance. Organizational officials report cyber security incidents to the United States Computer Emergency Readiness Team (US-CERT) at http://www.us-cert.gov within the specified timeframe designated in the US-CERT Concept of Operations for Federal Cyber Security Incident Handling. In addition to incident information, weaknesses and vulnerabilities in the information system are reported to appropriate organizational officials in a timely manner to prevent security incidents. NIST Special Publication 800-61 provides guidance on incident reporting.\n

Changes from Rev 4

Control text eliminates ‘information system security' incidents Discussion significantly revised

Enhancements

(1) The organization employs automated mechanisms to assist in the reporting of security incidents.\n

Compliance Mappings

ISO 27002:2022

5.56.8

COBIT 2019

DSS02.07EDM05.02

CIS Controls v8

17.2

NIST CSF 2.0

DE.AE-06RSRS.CORS.CO-02RS.CO-03RS.MA-01

SOC 2 TSC

CC2.2-POF4CC2.2-POF6CC2.3CC2.3-POF1CC2.3-POF8CC3.1-POF10CC7.3-POF2CC7.4CC7.4-POF13CC7.4-POF6CC7.4-POF9CC7.5-POF2P6.3P6.7

ISO 17799 (legacy)

6.1.66.2.26.2.313.1.113.1.2

COBIT 4.1 (legacy)

DS5.6