Skip to content

RESPOND (RS)

Actions regarding a detected cybersecurity incident are taken

Informative References

  • CRI Profile v2.0: RS
  • CSF v1.1: RS
  • ISO/IEC 27001:2022: Mandatory Clause: None
  • ISO/IEC 27001:2022: Annex A Controls: 5.26
  • SCF: IRO-01
  • SCF: IRO-02
  • SCF: IRO-04
  • SCF: IRO-07
  • SCF: IRO-09
  • SCF: IRO-10

Incident Management (RS.MA)

Responses to detected cybersecurity incidents are managed

Informative References

  • CRI Profile v2.0: RS.MA
  • CSF v1.1: RS.RP
  • ISO/IEC 27001:2022: Mandatory Clause: None
  • ISO/IEC 27001:2022: Annex A Controls: 5.24
  • ISO/IEC 27001:2022: Annex A Controls: 5.25
  • ISO/IEC 27001:2022: Annex A Controls: 5.26
  • ISO/IEC 27001:2022: Annex A Controls: 5.27
  • ISO/IEC 27001:2022: Annex A Controls: 5.28
  • NICE Framework: IO-WRL-005
  • NICE Framework: IO-WRL-006
  • NICE Framework: IO-WRL-007
  • NICE Framework: OG-WRL-007
  • NICE Framework: OG-WRL-010
  • NICE Framework: OG-WRL-015
  • NICE Framework: PD-WRL-001
  • NICE Framework: PD-WRL-002
  • NICE Framework: PD-WRL-003
  • NICE Framework: PD-WRL-004
  • NICE Framework: PD-WRL-005
  • NICE Framework: PD-WRL-006
  • NICE Framework: PD-WRL-007
  • SCF: IRO-02
  • SCF: IRO-04
  • SCF: IRO-07
  • SP 800-171 Rev 3: 03.06.01
  • SP 800-171 Rev 3: 03.06.02
  • SP 800-171 Rev 3: 03.06.05
  • SP 800-53 Rev 5.1.1: IR-04
  • SP 800-53 Rev 5.1.1: IR-07
  • SP 800-53 Rev 5.1.1: IR-08
  • SP 800-53 Rev 5.1.1: IR-09
  • SP 800-53 Rev 5.2.0: IR-04
  • SP 800-53 Rev 5.2.0: IR-07
  • SP 800-53 Rev 5.2.0: IR-08
  • SP 800-53 Rev 5.2.0: IR-09

RS.MA-01

The incident response plan is executed in coordination with relevant third parties once an incident is declared

Implementation Examples

  • Ex1: Detection technologies automatically report confirmed incidents
  • Ex2: Request incident response assistance from the organization's incident response outsourcer
  • Ex3: Designate an incident lead for each incident
  • Ex4: Initiate execution of additional cybersecurity plans as needed to support incident response (for example, business continuity and disaster recovery)

Informative References

  • AI-SOC: AI-SOC-12
  • AI-SOC: AI-SOC-04
  • CCMv4.0: BCR-07
  • CCMv4.0: IVS-09
  • CCMv4.0: SEF-01
  • CCMv4.0: SEF-03
  • CCMv4.0: SEF-07
  • CIS Controls v8.0: 17.4
  • CIS Controls v8.1: 17.4
  • CRI Profile v2.0: RS.MA-01
  • CRI Profile v2.0: RS.MA-01.01
  • CSF v1.1: RS.RP-1
  • CSF v1.1: RS.CO-4
  • CoP: D1
  • IRP: IRP-Sec-6
  • ISO/IEC 27001:2022: Mandatory Clause: None
  • ISO/IEC 27001:2022: Annex A Controls: 5.26
  • ISO/IEC 27001:2022: Annex A Controls: 5.27
  • ISO/IEC 27001:2022: Annex A Controls: 5.28
  • ISO/IEC 27001:2022: Control 5.26
  • NICE Framework: IO-WRL-005
  • NICE Framework: IO-WRL-007
  • NICE Framework: OG-WRL-007
  • NICE Framework: OG-WRL-010
  • NICE Framework: PD-WRL-001
  • NICE Framework: PD-WRL-003
  • NICE Framework: PD-WRL-004
  • OWASP Top 10 LLM Applications: LLM01-2025
  • OWASP Top 10 LLM Applications: LLM02-2025
  • OWASP Top 10 LLM Applications: LLM04-2025
  • PCI DSS: 12.10.1
  • PCI DSS: 12.10.3
  • PCI DSS: 12.10.2
  • PCI DSS: 12.8.2
  • SCF: IRO-02
  • SCF: IRO-02.5
  • SCF: IRO-04
  • SCF: IRO-07
  • SCF: IRO-10
  • SP 800-171 Rev 3: 03.06.02
  • SP 800-171 Rev 3: 03.06.05
  • SP 800-171 Rev 3: 03.17.03
  • SP 800-53 Rev 5.1.1: IR-06
  • SP 800-53 Rev 5.1.1: IR-07
  • SP 800-53 Rev 5.1.1: IR-08
  • SP 800-53 Rev 5.1.1: SR-03
  • SP 800-53 Rev 5.1.1: SR-08
  • SP 800-53 Rev 5.2.0: IR-06
  • SP 800-53 Rev 5.2.0: IR-07
  • SP 800-53 Rev 5.2.0: IR-08
  • SP 800-53 Rev 5.2.0: SR-03
  • SP 800-53 Rev 5.2.0: SR-08

RS.MA-02

Incident reports are triaged and validated

Implementation Examples

  • Ex1: Preliminarily review incident reports to confirm that they are cybersecurity-related and necessitate incident response activities
  • Ex2: Apply criteria to estimate the severity of an incident

Informative References

  • AI-SOC: AI-SOC-04
  • AI-SOC: AI-SOC-06
  • CCMv4.0: SEF-06
  • CRI Profile v2.0: RS.MA-02
  • CRI Profile v2.0: RS.MA-02.01
  • CSF v1.1: RS.AN-1
  • CSF v1.1: RS.AN-2
  • CoP: D3
  • Guardian-SDK: GS-PF-04
  • ISO/IEC 27001:2022: Mandatory Clause: None
  • ISO/IEC 27001:2022: Annex A Controls: 5.24
  • ISO/IEC 27001:2022: Annex A Controls: 5.26
  • ISO/IEC 27001:2022: Annex A Controls: 5.27
  • ISO/IEC 27001:2022: Annex A Controls: 5.28
  • ISO/IEC 27001:2022: Annex A Controls: 6.8
  • NICE Framework: IO-WRL-005
  • NICE Framework: IO-WRL-006
  • NICE Framework: IO-WRL-007
  • NICE Framework: PD-WRL-001
  • NICE Framework: PD-WRL-002
  • NICE Framework: PD-WRL-003
  • NICE Framework: PD-WRL-005
  • OWASP Top 10 LLM Applications: LLM01-2025
  • OWASP Top 10 LLM Applications: LLM02-2025
  • PCI DSS: 10.4.1
  • PCI DSS: 10.2.1
  • PCI DSS: 12.10.1
  • PCI DSS: 12.10.4
  • SCF: IRO-02
  • SCF: IRO-04
  • SDOS: SDOS-AU-01
  • SDOS: SDOS-RS-01
  • SP 800-171 Rev 3: 03.06.01
  • SP 800-171 Rev 3: 03.06.02
  • SP 800-53 Rev 5.1.1: IR-04
  • SP 800-53 Rev 5.1.1: IR-05
  • SP 800-53 Rev 5.1.1: IR-06
  • SP 800-53 Rev 5.2.0: IR-04
  • SP 800-53 Rev 5.2.0: IR-05
  • SP 800-53 Rev 5.2.0: IR-06

RS.MA-03

Incidents are categorized and prioritized

Implementation Examples

  • Ex1: Further review and categorize incidents based on the type of incident (e.g., data breach, ransomware, DDoS, account compromise)
  • Ex2: Prioritize incidents based on their scope, likely impact, and time-critical nature
  • Ex3: Select incident response strategies for active incidents by balancing the need to quickly recover from an incident with the need to observe the attacker or conduct a more thorough investigation

Informative References

  • CCMv4.0: SEF-02
  • CCMv4.0: SEF-06
  • CRI Profile v2.0: RS.MA-03
  • CRI Profile v2.0: RS.MA-03.01
  • CSF v1.1: RS.AN-4
  • CSF v1.1: RS.AN-2
  • Guardian-SDK: GS-PF-04
  • ISO/IEC 27001:2022: Mandatory Clause: None
  • ISO/IEC 27001:2022: Annex A Controls: 5.25
  • NICE Framework: IO-WRL-005
  • NICE Framework: IO-WRL-006
  • NICE Framework: IO-WRL-007
  • NICE Framework: PD-WRL-001
  • NICE Framework: PD-WRL-002
  • NICE Framework: PD-WRL-003
  • NICE Framework: PD-WRL-006
  • PCI DSS: 12.10.1
  • PCI DSS: 10.4.1
  • PCI DSS: 12.10.2
  • PCI DSS: 12.10.6
  • SCF: IRO-02.4
  • SDOS: SDOS-AU-01
  • SDOS: SDOS-RM-01
  • SP 800-171 Rev 3: 03.06.01
  • SP 800-171 Rev 3: 03.06.02
  • SP 800-53 Rev 5.1.1: IR-04
  • SP 800-53 Rev 5.1.1: IR-05
  • SP 800-53 Rev 5.1.1: IR-06
  • SP 800-53 Rev 5.2.0: IR-04
  • SP 800-53 Rev 5.2.0: IR-05
  • SP 800-53 Rev 5.2.0: IR-06

RS.MA-04

Incidents are escalated or elevated as needed

Implementation Examples

  • Ex1: Track and validate the status of all ongoing incidents
  • Ex2: Coordinate incident escalation or elevation with designated internal and external stakeholders

Informative References

  • CCMv4.0: SEF-02
  • CRI Profile v2.0: RS.MA-04
  • CRI Profile v2.0: RS.MA-04.01
  • CSF v1.1: RS.AN-2
  • CSF v1.1: RS.CO-4
  • ISO/IEC 27001:2022: Mandatory Clause: None
  • ISO/IEC 27001:2022: Annex A Controls: 5.26
  • NICE Framework: IO-WRL-005
  • NICE Framework: IO-WRL-006
  • NICE Framework: IO-WRL-007
  • NICE Framework: PD-WRL-001
  • NICE Framework: PD-WRL-003
  • NICE Framework: PD-WRL-007
  • PCI DSS: 12.10.3
  • PCI DSS: 12.10.1
  • PCI DSS: 12.10.2
  • SCF: IRO-02
  • SCF: IRO-04
  • SCF: IRO-07
  • SDOS: SDOS-DE-01
  • SDOS: SDOS-RM-01
  • SP 800-171 Rev 3: 03.06.01
  • SP 800-171 Rev 3: 03.06.02
  • SP 800-53 Rev 5.1.1: IR-04
  • SP 800-53 Rev 5.1.1: IR-05
  • SP 800-53 Rev 5.1.1: IR-06
  • SP 800-53 Rev 5.1.1: IR-07
  • SP 800-53 Rev 5.2.0: IR-04
  • SP 800-53 Rev 5.2.0: IR-05
  • SP 800-53 Rev 5.2.0: IR-06
  • SP 800-53 Rev 5.2.0: IR-07

RS.MA-05

The criteria for initiating incident recovery are applied

Implementation Examples

  • Ex1: Apply incident recovery criteria to known and assumed characteristics of the incident to determine whether incident recovery processes should be initiated
  • Ex2: Take the possible operational disruption of incident recovery activities into account

Informative References

  • AI-SOC: AI-SOC-12
  • AI-SOC: AI-SOC-04
  • CCMv4.0: SEF-02
  • CIS Controls v8.0: 17.9
  • CIS Controls v8.1: 17.9
  • CRI Profile v2.0: RS.MA-05
  • CRI Profile v2.0: RS.MA-05.01
  • ISO/IEC 27001:2022: Mandatory Clause: None
  • ISO/IEC 27001:2022: Annex A Controls: 5.25
  • NICE Framework: IO-WRL-005
  • NICE Framework: IO-WRL-007
  • NICE Framework: OG-WRL-007
  • NICE Framework: OG-WRL-010
  • NICE Framework: OG-WRL-015
  • NICE Framework: PD-WRL-001
  • NICE Framework: PD-WRL-003
  • OWASP Top 10 LLM Applications: LLM04-2025
  • PCI DSS: 12.10.1
  • PCI DSS: 12.10.2
  • PCI DSS: 12.10.6
  • SCF: BCD-01
  • SDOS: SDOS-AU-01
  • SDOS: SDOS-RM-01
  • SDOS: SDOS-RS-01
  • SP 800-171 Rev 3: 03.06.01
  • SP 800-171 Rev 3: 03.06.05
  • SP 800-53 Rev 5.1.1: IR-04
  • SP 800-53 Rev 5.1.1: IR-08
  • SP 800-53 Rev 5.2.0: IR-04
  • SP 800-53 Rev 5.2.0: IR-08

Incident Analysis (RS.AN)

Investigations are conducted to ensure effective response and support forensics and recovery activities

Informative References

  • CRI Profile v2.0: RS.AN
  • CSF v1.1: RS.AN
  • ISO/IEC 27001:2022: Mandatory Clause: None
  • ISO/IEC 27001:2022: Annex A Controls: 5.26
  • ISO/IEC 27001:2022: Annex A Controls: 5.28
  • NICE Framework: IO-WRL-001
  • NICE Framework: IO-WRL-002
  • NICE Framework: IO-WRL-003
  • NICE Framework: IO-WRL-006
  • NICE Framework: OG-WRL-012
  • NICE Framework: PD-WRL-002
  • NICE Framework: PD-WRL-003
  • NICE Framework: PD-WRL-004
  • SCF: IRO-02
  • SCF: IRO-08
  • SP-800-37 Rev 2: RMF Monitor Step: TASK M-3 Ongoing Risk Response

RS.AN-01

[Withdrawn: Incorporated into RS.MA-02]

RS.AN-02

[Withdrawn: Incorporated into RS.MA-02, RS.MA-03, RS.MA-04]

RS.AN-03

Analysis is performed to establish what has taken place during an incident and the root cause of the incident

Implementation Examples

  • Ex1: Determine the sequence of events that occurred during the incident and which assets and resources were involved in each event
  • Ex2: Attempt to determine what vulnerabilities, threats, and threat actors were directly or indirectly involved in the incident
  • Ex3: Analyze the incident to find the underlying, systemic root causes
  • Ex4: Check any cyber deception technology for additional information on attacker behavior

Informative References

  • AI-SOC: AI-SOC-23
  • AI-SOC: AI-SOC-13
  • CCMv4.0: SEF-06
  • CIS Controls v8.0: 17.8
  • CIS Controls v8.1: 17.8
  • CRI Profile v2.0: RS.AN-03
  • CRI Profile v2.0: RS.AN-03.01
  • CSF v1.1: RS.AN-3
  • CoP: D4
  • ISO/IEC 27001:2022: Mandatory Clause: None
  • ISO/IEC 27001:2022: Annex A Controls: 5.25
  • ISO/IEC 27001:2022: Annex A Controls: 5.27
  • NICE Framework: IO-WRL-001
  • NICE Framework: IO-WRL-003
  • NICE Framework: IO-WRL-006
  • NICE Framework: OG-WRL-012
  • NICE Framework: PD-WRL-002
  • NICE Framework: PD-WRL-003
  • NICE Framework: PD-WRL-004
  • OWASP Top 10 LLM Applications: LLM01-2025
  • OWASP Top 10 LLM Applications: LLM04-2025
  • OWASP Top 10 LLM Applications: LLM05-2025
  • PCI DSS: 10.2.1
  • PCI DSS: 10.4.1
  • PCI DSS: 6.3.1
  • PCI DSS: 10.2.2
  • SCF: IRO-13
  • SDOS: SDOS-AU-01
  • SDOS: SDOS-AU-02
  • SDOS: SDOS-DE-02
  • SDOS: SDOS-RS-01
  • SP 800-171 Rev 3: 03.03.06
  • SP 800-171 Rev 3: 03.06.01
  • SP 800-53 Rev 5.1.1: AU-07
  • SP 800-53 Rev 5.1.1: IR-04
  • SP 800-53 Rev 5.2.0: AU-07
  • SP 800-53 Rev 5.2.0: IR-04
  • SP 800-53 Rev 5.2.0: SI-02(07)

RS.AN-04

[Withdrawn: Moved to RS.MA-03]

RS.AN-05

[Withdrawn: Moved to ID.RA-08]

RS.AN-06

Actions performed during an investigation are recorded, and the records' integrity and provenance are preserved

Implementation Examples

  • Ex1: Require each incident responder and others (e.g., system administrators, cybersecurity engineers) who perform incident response tasks to record their actions and make the record immutable
  • Ex2: Require the incident lead to document the incident in detail and be responsible for preserving the integrity of the documentation and the sources of all information being reported

Informative References

  • CRI Profile v2.0: RS.AN-06
  • CRI Profile v2.0: RS.AN-06.01
  • CSF v1.1: RS.AN-3
  • Guardian-SDK: GS-CF-02
  • ISO/IEC 27001:2022: Mandatory Clause: None
  • ISO/IEC 27001:2022: Annex A Controls: 5.28
  • NICE Framework: IO-WRL-001
  • NICE Framework: IO-WRL-002
  • NICE Framework: IO-WRL-003
  • NICE Framework: IO-WRL-006
  • NICE Framework: PD-WRL-002
  • NICE Framework: PD-WRL-003
  • NICE Framework: PD-WRL-004
  • PCI DSS: 10.3.2
  • PCI DSS: 10.3.1
  • PCI DSS: 10.3.3
  • PCI DSS: 10.3.4
  • PCI DSS: 10.6.1
  • PCI DSS: 10.5.1
  • SCF: IRO-02
  • SCF: IRO-08
  • SCF: IRO-09
  • SDOS: SDOS-AU-01
  • SDOS: SDOS-AU-03
  • SP 800-171 Rev 3: 03.03.06
  • SP 800-171 Rev 3: 03.06.01
  • SP 800-171 Rev 3: 03.06.02
  • SP 800-53 Rev 5.1.1: AU-07
  • SP 800-53 Rev 5.1.1: IR-04
  • SP 800-53 Rev 5.1.1: IR-06
  • SP 800-53 Rev 5.2.0: AU-07
  • SP 800-53 Rev 5.2.0: IR-04
  • SP 800-53 Rev 5.2.0: IR-06

RS.AN-07

Incident data and metadata are collected, and their integrity and provenance are preserved

Implementation Examples

  • Ex1: Collect, preserve, and safeguard the integrity of all pertinent incident data and metadata (e.g., data source, date/time of collection) based on evidence preservation and chain-of-custody procedures

Informative References

  • AI-SOC: AI-SOC-23
  • AI-SOC: AI-SOC-22
  • CRI Profile v2.0: RS.AN-07
  • CRI Profile v2.0: RS.AN-07.01
  • ISO/IEC 27001:2022: Mandatory Clause: None
  • ISO/IEC 27001:2022: Annex A Controls: 5.28
  • ISO/IEC 27001:2022: Control 5.28
  • NICE Framework: IO-WRL-001
  • NICE Framework: IO-WRL-002
  • NICE Framework: IO-WRL-003
  • NICE Framework: IO-WRL-006
  • NICE Framework: PD-WRL-002
  • NICE Framework: PD-WRL-003
  • NICE Framework: PD-WRL-004
  • OWASP Top 10 LLM Applications: LLM02-2025
  • OWASP Top 10 LLM Applications: LLM04-2025
  • PCI DSS: 10.2.1
  • PCI DSS: 10.3.2
  • PCI DSS: 10.3.3
  • PCI DSS: 10.6.1
  • PCI DSS: 10.2.2
  • SCF: IRO-08
  • SDOS: SDOS-AU-01
  • SDOS: SDOS-AU-03
  • SP 800-171 Rev 3: 03.03.06
  • SP 800-171 Rev 3: 03.06.01
  • SP 800-171 Rev 3: 03.06.02
  • SP 800-53 Rev 5.1.1: AU-07
  • SP 800-53 Rev 5.1.1: IR-04
  • SP 800-53 Rev 5.1.1: IR-06
  • SP 800-53 Rev 5.2.0: AU-07
  • SP 800-53 Rev 5.2.0: IR-04
  • SP 800-53 Rev 5.2.0: IR-06
  • SP 800-81r3: 2.1.3

RS.AN-08

An incident's magnitude is estimated and validated

Implementation Examples

  • Ex1: Review other potential targets of the incident to search for indicators of compromise and evidence of persistence
  • Ex2: Automatically run tools on targets to look for indicators of compromise and evidence of persistence

Informative References

  • AI-SOC: AI-SOC-06
  • AI-SOC: AI-SOC-17
  • CRI Profile v2.0: RS.AN-08
  • CRI Profile v2.0: RS.AN-08.01
  • ISO/IEC 27001:2022: Mandatory Clause: None
  • ISO/IEC 27001:2022: Annex A Controls: 5.25
  • NICE Framework: IO-WRL-001
  • NICE Framework: IO-WRL-003
  • NICE Framework: IO-WRL-006
  • NICE Framework: OG-WRL-012
  • NICE Framework: PD-WRL-003
  • NICE Framework: PD-WRL-004
  • OWASP Top 10 LLM Applications: LLM02-2025
  • OWASP Top 10 LLM Applications: LLM04-2025
  • PCI DSS: 10.4.1
  • PCI DSS: 1.2.3
  • PCI DSS: 1.2.4
  • PCI DSS: 12.5.1
  • SCF: IRO-02.4
  • SDOS: SDOS-AU-01
  • SDOS: SDOS-RM-01
  • SP 800-171 Rev 3: 03.06.01
  • SP 800-171 Rev 3: 03.06.05
  • SP 800-171 Rev 3: 03.11.01
  • SP 800-171 Rev 3: 03.11.04
  • SP 800-53 Rev 5.1.1: IR-04
  • SP 800-53 Rev 5.1.1: IR-08
  • SP 800-53 Rev 5.1.1: RA-03
  • SP 800-53 Rev 5.1.1: RA-07
  • SP 800-53 Rev 5.2.0: IR-04
  • SP 800-53 Rev 5.2.0: IR-08
  • SP 800-53 Rev 5.2.0: RA-03
  • SP 800-53 Rev 5.2.0: RA-07

Incident Response Reporting and Communication (RS.CO)

Response activities are coordinated with internal and external stakeholders as required by laws, regulations, or policies

Informative References

  • CRI Profile v2.0: RS.CO
  • CSF v1.1: RS.CO
  • ISO/IEC 27001:2022: Mandatory Clause: None
  • ISO/IEC 27001:2022: Annex A Controls: 5.26
  • NICE Framework: OG-WRL-006
  • NICE Framework: OG-WRL-007
  • NICE Framework: OG-WRL-008
  • NICE Framework: OG-WRL-010
  • NICE Framework: OG-WRL-015
  • NICE Framework: PD-WRL-003
  • SCF: IRO-02
  • SCF: IRO-02.5
  • SCF: IRO-06.1
  • SCF: IRO-09
  • SCF: IRO-10
  • SCF: IRO-10.4
  • SP-800-37 Rev 2: RMF Monitor Step: TASK M-3 Ongoing Risk Response

RS.CO-01

[Withdrawn: Incorporated into PR.AT-01]

RS.CO-02

Internal and external stakeholders are notified of incidents

Implementation Examples

  • Ex1: Follow the organization's breach notification procedures after discovering a data breach incident, including notifying affected customers
  • Ex2: Notify business partners and customers of incidents in accordance with contractual requirements
  • Ex3: Notify law enforcement agencies and regulatory bodies of incidents based on criteria in the incident response plan and management approval

Informative References

  • AI-SOC: AI-SOC-30
  • AI-SOC: AI-SOC-12
  • CCMv4.0: DSP-18
  • CCMv4.0: SEF-02
  • CCMv4.0: SEF-07
  • CCMv4.0: SEF-08
  • CIS Controls v8.0: 17.2
  • CIS Controls v8.1: 17.2
  • CRI Profile v2.0: RS.CO-02
  • CRI Profile v2.0: RS.CO-02.01
  • CRI Profile v2.0: RS.CO-02.02
  • CRI Profile v2.0: RS.CO-02.03
  • CSF v1.1: RS.CO-2
  • CSF v1.1: RS.CO-3
  • Guardian-SDK: GS-CF-02
  • ISO/IEC 27001:2022: Mandatory Clause: 7.4
  • ISO/IEC 27001:2022: Annex A Controls: 5.26
  • NICE Framework: OG-WRL-006
  • NICE Framework: OG-WRL-007
  • NICE Framework: OG-WRL-008
  • NICE Framework: OG-WRL-010
  • NICE Framework: OG-WRL-015
  • NICE Framework: PD-WRL-003
  • OWASP Top 10 LLM Applications: LLM02-2025
  • PCI DSS: 12.10.1
  • PCI DSS: 12.10.3
  • PCI DSS: 12.8.2
  • PCI DSS: 12.8.5
  • SCF: IRO-02
  • SCF: IRO-10
  • SCF: IRO-10.4
  • SDOS: SDOS-AU-03
  • SP 800-171 Rev 3: 03.06.01
  • SP 800-171 Rev 3: 03.06.02
  • SP 800-171 Rev 3: 03.17.03
  • SP 800-53 Rev 5.1.1: IR-04
  • SP 800-53 Rev 5.1.1: IR-06
  • SP 800-53 Rev 5.1.1: IR-07
  • SP 800-53 Rev 5.1.1: SR-03
  • SP 800-53 Rev 5.1.1: SR-08
  • SP 800-53 Rev 5.2.0: IR-04
  • SP 800-53 Rev 5.2.0: IR-06
  • SP 800-53 Rev 5.2.0: IR-07
  • SP 800-53 Rev 5.2.0: SR-03
  • SP 800-53 Rev 5.2.0: SR-08

RS.CO-03

Information is shared with designated internal and external stakeholders

Implementation Examples

  • Ex1: Securely share information consistent with response plans and information sharing agreements
  • Ex2: Voluntarily share information about an attacker's observed TTPs, with all sensitive data removed, with an Information Sharing and Analysis Center (ISAC)
  • Ex3: Notify HR when malicious insider activity occurs
  • Ex4: Regularly update senior leadership on the status of major incidents
  • Ex5: Follow the rules and protocols defined in contracts for incident information sharing between the organization and its suppliers
  • Ex6: Coordinate crisis communication methods between the organization and its critical suppliers

Informative References

  • AI-SOC: AI-SOC-30
  • AI-SOC: AI-SOC-12
  • CCMv4.0: BCR-07
  • CCMv4.0: DSP-18
  • CCMv4.0: SEF-07
  • CCMv4.0: SEF-08
  • CIS Controls v8.0: 17.2
  • CIS Controls v8.1: 17.2
  • CRI Profile v2.0: RS.CO-03
  • CRI Profile v2.0: RS.CO-03.01
  • CRI Profile v2.0: RS.CO-03.02
  • CSF v1.1: RS.CO-3
  • CSF v1.1: RS.CO-5
  • ISO/IEC 27001:2022: Mandatory Clause: 7.4
  • ISO/IEC 27001:2022: Annex A Controls: 5.26
  • NICE Framework: OG-WRL-006
  • NICE Framework: OG-WRL-007
  • NICE Framework: OG-WRL-008
  • NICE Framework: OG-WRL-010
  • NICE Framework: OG-WRL-015
  • NICE Framework: PD-WRL-003
  • OWASP Top 10 LLM Applications: LLM02-2025
  • OWASP Top 10 LLM Applications: LLM03-2025
  • PCI DSS: 12.10.1
  • PCI DSS: 12.8.2
  • PCI DSS: 12.8.4
  • PCI DSS: 12.10.6
  • SCF: IRO-02
  • SCF: IRO-10
  • SCF: IRO-10.4
  • SDOS: SDOS-AU-03
  • SP 800-171 Rev 3: 03.06.01
  • SP 800-171 Rev 3: 03.06.02
  • SP 800-171 Rev 3: 03.17.03
  • SP 800-53 Rev 5.1.1: IR-04
  • SP 800-53 Rev 5.1.1: IR-06
  • SP 800-53 Rev 5.1.1: IR-07
  • SP 800-53 Rev 5.1.1: SR-03
  • SP 800-53 Rev 5.1.1: SR-08
  • SP 800-53 Rev 5.2.0: IR-04
  • SP 800-53 Rev 5.2.0: IR-06
  • SP 800-53 Rev 5.2.0: IR-07
  • SP 800-53 Rev 5.2.0: SR-03
  • SP 800-53 Rev 5.2.0: SR-08
  • SP 800-81r3: 2.3.3
  • SP 800-81r3: 3.4.2

RS.CO-04

[Withdrawn: Incorporated into RS.MA-01, RS.MA-04]

RS.CO-05

[Withdrawn: Incorporated into RS.CO-03]

Incident Mitigation (RS.MI)

Activities are performed to prevent expansion of an event and mitigate its effects

Informative References

  • CRI Profile v2.0: RS.MI
  • CSF v1.1: RS.MI
  • ISO/IEC 27001:2022: Mandatory Clause: None
  • ISO/IEC 27001:2022: Annex A Controls: 5.26
  • NICE Framework: DD-WRL-001
  • NICE Framework: IO-WRL-005
  • NICE Framework: IO-WRL-007
  • NICE Framework: OG-WRL-014
  • NICE Framework: PD-WRL-003
  • NICE Framework: PD-WRL-004
  • SCF: IRO-01
  • SCF: IRO-02
  • SCF: IRO-04
  • SP-800-37 Rev 2: RMF Monitor Step: TASK M-3 Ongoing Risk Response

RS.MI-01

Incidents are contained

Implementation Examples

  • Ex1: Cybersecurity technologies (e.g., antivirus software) and cybersecurity features of other technologies (e.g., operating systems, network infrastructure devices) automatically perform containment actions
  • Ex2: Allow incident responders to manually select and perform containment actions
  • Ex3: Allow a third party (e.g., internet service provider, managed security service provider) to perform containment actions on behalf of the organization
  • Ex4: Automatically transfer compromised endpoints to a remediation virtual local area network (VLAN)

Informative References

  • AI-SOC: AI-SOC-07
  • AI-SOC: AI-SOC-24
  • BXAIOS: Chapter 7 - Deploy the Governor
  • CCMv4.0: CEK-19
  • CCMv4.0: CEK-20
  • CCMv4.0: IVS-09
  • CCMv4.0: SEF-02
  • CCMv4.0: UEM-09
  • CRI Profile v2.0: RS.MI-01
  • CRI Profile v2.0: RS.MI-01.01
  • CSF v1.1: RS.MI-1
  • Guardian-SDK: GS-PF-01
  • Guardian-SDK: GS-PO-01
  • Guardian-SDK: GS-AG-01
  • IRP: IRP-Sec-5
  • ISO/IEC 27001:2022: Mandatory Clause: None
  • ISO/IEC 27001:2022: Annex A Controls: 5.26
  • NICE Framework: DD-WRL-001
  • NICE Framework: IO-WRL-005
  • NICE Framework: IO-WRL-007
  • NICE Framework: OG-WRL-014
  • NICE Framework: PD-WRL-003
  • NICE Framework: PD-WRL-004
  • OWASP Top 10 LLM Applications: LLM01-2025
  • OWASP Top 10 LLM Applications: LLM04-2025
  • OWASP Top 10 LLM Applications: LLM06-2025
  • OWASP Top 10 LLM Applications: LLM10-2025
  • PCI DSS: 12.10.1
  • PCI DSS: 5.2.1
  • PCI DSS: 5.2.2
  • PCI DSS: 5.3.2
  • SCF: IRO-02
  • SDOS: SDOS-EN-01
  • SDOS: SDOS-EN-03
  • SDOS: SDOS-IN-02
  • SP 800-171 Rev 3: 03.06.01
  • SP 800-53 Rev 5.1.1: IR-04
  • SP 800-53 Rev 5.2.0: IR-04
  • SP 800-81r3: 3.6.3

RS.MI-02

Incidents are eradicated

Implementation Examples

  • Ex1: Cybersecurity technologies and cybersecurity features of other technologies (e.g., operating systems, network infrastructure devices) automatically perform eradication actions
  • Ex2: Allow incident responders to manually select and perform eradication actions
  • Ex3: Allow a third party (e.g., managed security service provider) to perform eradication actions on behalf of the organization

Informative References

  • AI-SOC: AI-SOC-24
  • AI-SOC: AI-SOC-08
  • CCMv4.0: CEK-19
  • CCMv4.0: IVS-09
  • CCMv4.0: SEF-02
  • CCMv4.0: SEF-06
  • CRI Profile v2.0: RS.MI-02
  • CRI Profile v2.0: RS.MI-02.01
  • CSF v1.1: RS.MI-2
  • ISO/IEC 27001:2022: Mandatory Clause: None
  • ISO/IEC 27001:2022: Annex A Controls: 5.26
  • NICE Framework: DD-WRL-001
  • NICE Framework: IO-WRL-005
  • NICE Framework: IO-WRL-007
  • NICE Framework: OG-WRL-014
  • NICE Framework: PD-WRL-003
  • NICE Framework: PD-WRL-004
  • OWASP Top 10 LLM Applications: LLM01-2025
  • OWASP Top 10 LLM Applications: LLM03-2025
  • OWASP Top 10 LLM Applications: LLM04-2025
  • PCI DSS: 12.10.1
  • PCI DSS: 6.3.3
  • PCI DSS: 5.2.2
  • PCI DSS: 6.2.3
  • PCI DSS: 2.2.1
  • SCF: IRO-02
  • SDOS: SDOS-GV-01
  • SDOS: SDOS-IA-02
  • SP 800-171 Rev 3: 03.06.01
  • SP 800-53 Rev 5.1.1: IR-04
  • SP 800-53 Rev 5.2.0: IR-04

RS.MI-03

[Withdrawn: Incorporated into ID.RA-06]

Response Planning (RS.RP)

[Withdrawn: Incorporated into RS.MA]

RS.RP-01

[Withdrawn: Incorporated into RS.MA-01]

Improvements (RS.IM)

[Withdrawn: Incorporated into ID.IM]

RS.IM-01

[Withdrawn: Incorporated into ID.IM-03, ID.IM-04]

RS.IM-02

[Withdrawn: Incorporated into ID.IM-03]