Incident Response (IR)¶
Domain: Incident Response (IR)
Requirements in this domain: 3
Assessment Objectives in this domain: 14
IR.L2-3.6.1¶
IR.L2-3.6.1[a]¶
Assessment Objective
an operational incident-handling capability is established.
Collection Approach: Document
Potential Evidence Examples
Incident Response Plan/SOP describing the organization's operational incident-handling capability from detection through closure.
Assessment Guide – Further Discussion
Is there an incident response policy which specifically outlines requirements for handling of incidents involving CUI [a]?
IR.L2-3.6.1[b]¶
Assessment Objective
the operational incident-handling capability includes preparation.
Collection Approach: Document
Potential Evidence Examples
Incident Response Plan/SOP section addressing preparation (e.g., IR team roles, tools, training, and communication plans established before an incident occurs), supported by IR training records or a Continuity of Operations (COOP) plan reference.
IR.L2-3.6.1[c]¶
Assessment Objective
the operational incident-handling capability includes detection.
Collection Approach: Document
Potential Evidence Examples
Incident Response Plan/SOP section describing detection capabilities and the tools used (e.g., SIEM alerts, EDR, IDS/IPS), supported by an example alert or prior detection artifact.
IR.L2-3.6.1[d]¶
Assessment Objective
the operational incident-handling capability includes analysis.
Collection Approach: Document
Potential Evidence Examples
Incident Response Plan/SOP section describing the analysis process and tools used to triage and scope a suspected incident, supported by a prior incident analysis artifact if available.
IR.L2-3.6.1[e]¶
Assessment Objective
the operational incident-handling capability includes containment.
Collection Approach: Document
Potential Evidence Examples
Incident Response Plan/SOP section describing containment actions (e.g., network isolation, account disablement, quarantine procedures) and any related user-notification/training materials.
IR.L2-3.6.1[f]¶
Assessment Objective
the operational incident-handling capability includes recovery.
Collection Approach: Document
Potential Evidence Examples
Incident Response Plan/SOP section describing recovery actions (e.g., restoring from clean backups, re-imaging/re-baselining affected systems), supported by a COOP reference or a prior after-action recovery record.
IR.L2-3.6.1[g]¶
Assessment Objective
the operational incident-handling capability includes user response activities.
Collection Approach: Document
Potential Evidence Examples
Incident Response Plan/SOP section describing expected user response activities (e.g., how a user reports a suspected incident), supported by security-awareness training content or Help Desk intake procedures covering incident reporting.
IR.L2-3.6.2¶
IR.L2-3.6.2[a]¶
Assessment Objective
incidents are tracked.
Collection Approach: Artifact
Potential Evidence Examples
Screen share of the incident-tracking mechanism (ITSM ticketing system or dedicated IR tracking tool) showing incidents are logged and tracked from open to closed status.
Assessment Guide – Further Discussion
Is there an incident response policy that directs the establishment of requirements for tracking and reporting of incidents involving CUI to appropriate officials [a,d]?
IR.L2-3.6.2[b]¶
Assessment Objective
incidents are documented.
Collection Approach: Artifact
Potential Evidence Examples
Sampled incident record/report showing required documentation elements are captured (e.g., discovery date, description, scope, actions taken, resolution).
IR.L2-3.6.2[c]¶
Assessment Objective
authorities to whom incidents are to be reported are identified.
Collection Approach: Document
Potential Evidence Examples
Incident Response Plan/SOP identifying the external authorities to whom certain incidents must be reported (e.g., DoD via DIBNet/DC3 for a cyber incident involving CUI, per DFARS 252.204-7012).
IR.L2-3.6.2[d]¶
Assessment Objective
organizational officials to whom incidents are to be reported are identified.
Collection Approach: Document
Potential Evidence Examples
Incident Response Plan/SOP identifying the internal organizational officials (e.g., ISSM, CISO, legal, executive leadership) who must be notified of incidents.
Assessment Guide – Further Discussion
Is there an incident response policy that directs the establishment of requirements for tracking and reporting of incidents involving CUI to appropriate officials [a,d]?
IR.L2-3.6.2[e]¶
Assessment Objective
identified authorities are notified of incidents.
Collection Approach: Screen Share
Potential Evidence Examples
Evidence of a prior external notification — e.g., a DIBNet submission confirmation, redacted incident report, or notification email to the identified external authority — or, absent a real incident, the documented notification procedure and contact information kept current.
IR.L2-3.6.2[f]¶
Assessment Objective
identified organizational officials are notified of incidents.
Collection Approach: Artifact
Potential Evidence Examples
Evidence of a prior internal notification to organizational officials — e.g., an email/ticket record — or, absent a real incident, a tabletop-exercise record demonstrating the internal notification chain was exercised.
Assessment Guide – Further Discussion
Is cybersecurity incident information promptly reported to management [e,f]?
IR.L2-3.6.3¶
IR.L2-3.6.3[a]¶
Assessment Objective
the incident response capability is tested.
Collection Approach: Artifact
Potential Evidence Examples
Documented results of an incident-response test — e.g., a tabletop exercise report, scheduled/unscheduled IR drill after-action report, or penetration test used to validate the IR capability — including date, participants, scenario, and lessons-learned/improvement actions.
Assessment Guide – Further Discussion
Does the incident response policy outline requirements for regular incident response plan testing and reviews of incident response capabilities [a]?