Skip to content

Incident Response (IR)

Domain: Incident Response (IR)
Requirements in this domain: 3
Assessment Objectives in this domain: 14


IR.L2-3.6.1

IR.L2-3.6.1[a]

Assessment Objective

an operational incident-handling capability is established.

Collection Approach: Document

Potential Evidence Examples

Incident Response Plan/SOP describing the organization's operational incident-handling capability from detection through closure.

Assessment Guide – Further Discussion

Is there an incident response policy which specifically outlines requirements for handling of incidents involving CUI [a]?


IR.L2-3.6.1[b]

Assessment Objective

the operational incident-handling capability includes preparation.

Collection Approach: Document

Potential Evidence Examples

Incident Response Plan/SOP section addressing preparation (e.g., IR team roles, tools, training, and communication plans established before an incident occurs), supported by IR training records or a Continuity of Operations (COOP) plan reference.


IR.L2-3.6.1[c]

Assessment Objective

the operational incident-handling capability includes detection.

Collection Approach: Document

Potential Evidence Examples

Incident Response Plan/SOP section describing detection capabilities and the tools used (e.g., SIEM alerts, EDR, IDS/IPS), supported by an example alert or prior detection artifact.


IR.L2-3.6.1[d]

Assessment Objective

the operational incident-handling capability includes analysis.

Collection Approach: Document

Potential Evidence Examples

Incident Response Plan/SOP section describing the analysis process and tools used to triage and scope a suspected incident, supported by a prior incident analysis artifact if available.


IR.L2-3.6.1[e]

Assessment Objective

the operational incident-handling capability includes containment.

Collection Approach: Document

Potential Evidence Examples

Incident Response Plan/SOP section describing containment actions (e.g., network isolation, account disablement, quarantine procedures) and any related user-notification/training materials.


IR.L2-3.6.1[f]

Assessment Objective

the operational incident-handling capability includes recovery.

Collection Approach: Document

Potential Evidence Examples

Incident Response Plan/SOP section describing recovery actions (e.g., restoring from clean backups, re-imaging/re-baselining affected systems), supported by a COOP reference or a prior after-action recovery record.


IR.L2-3.6.1[g]

Assessment Objective

the operational incident-handling capability includes user response activities.

Collection Approach: Document

Potential Evidence Examples

Incident Response Plan/SOP section describing expected user response activities (e.g., how a user reports a suspected incident), supported by security-awareness training content or Help Desk intake procedures covering incident reporting.


IR.L2-3.6.2

IR.L2-3.6.2[a]

Assessment Objective

incidents are tracked.

Collection Approach: Artifact

Potential Evidence Examples

Screen share of the incident-tracking mechanism (ITSM ticketing system or dedicated IR tracking tool) showing incidents are logged and tracked from open to closed status.

Assessment Guide – Further Discussion

Is there an incident response policy that directs the establishment of requirements for tracking and reporting of incidents involving CUI to appropriate officials [a,d]?


IR.L2-3.6.2[b]

Assessment Objective

incidents are documented.

Collection Approach: Artifact

Potential Evidence Examples

Sampled incident record/report showing required documentation elements are captured (e.g., discovery date, description, scope, actions taken, resolution).


IR.L2-3.6.2[c]

Assessment Objective

authorities to whom incidents are to be reported are identified.

Collection Approach: Document

Potential Evidence Examples

Incident Response Plan/SOP identifying the external authorities to whom certain incidents must be reported (e.g., DoD via DIBNet/DC3 for a cyber incident involving CUI, per DFARS 252.204-7012).


IR.L2-3.6.2[d]

Assessment Objective

organizational officials to whom incidents are to be reported are identified.

Collection Approach: Document

Potential Evidence Examples

Incident Response Plan/SOP identifying the internal organizational officials (e.g., ISSM, CISO, legal, executive leadership) who must be notified of incidents.

Assessment Guide – Further Discussion

Is there an incident response policy that directs the establishment of requirements for tracking and reporting of incidents involving CUI to appropriate officials [a,d]?


IR.L2-3.6.2[e]

Assessment Objective

identified authorities are notified of incidents.

Collection Approach: Screen Share

Potential Evidence Examples

Evidence of a prior external notification — e.g., a DIBNet submission confirmation, redacted incident report, or notification email to the identified external authority — or, absent a real incident, the documented notification procedure and contact information kept current.


IR.L2-3.6.2[f]

Assessment Objective

identified organizational officials are notified of incidents.

Collection Approach: Artifact

Potential Evidence Examples

Evidence of a prior internal notification to organizational officials — e.g., an email/ticket record — or, absent a real incident, a tabletop-exercise record demonstrating the internal notification chain was exercised.

Assessment Guide – Further Discussion

Is cybersecurity incident information promptly reported to management [e,f]?


IR.L2-3.6.3

IR.L2-3.6.3[a]

Assessment Objective

the incident response capability is tested.

Collection Approach: Artifact

Potential Evidence Examples

Documented results of an incident-response test — e.g., a tabletop exercise report, scheduled/unscheduled IR drill after-action report, or penetration test used to validate the IR capability — including date, participants, scenario, and lessons-learned/improvement actions.

Assessment Guide – Further Discussion

Does the incident response policy outline requirements for regular incident response plan testing and reviews of incident response capabilities [a]?