IR-4 — Incident Handling
Organizations recognize that incident response capabilities are dependent on the capabilities of organizational systems and the mission and business processes being supported by those systems. Organizations consider incident response as part of the definition, design, and development of mission and business processes and systems. Incident-related information can be obtained from a variety of sources, including audit monitoring, physical access monitoring, and network monitoring; user or administrator reports; and reported supply chain events. An effective incident handling capability includes coordination among many organizational entities (e.g., mission or business owners, system owners, authorizing officials, human resources offices, physical security offices, personnel security offices, legal departments, risk executive [function], operations personnel, procurement offices). Suspected
Read the official statement, discussion, parameters, enhancements, and assessment methods →
NIST CSF 2.0 informative references
These CSF Subcategories list this base control or one of its enhancements in the imported NIST informative reference.
Show 12 additional relationships
NIST SP 800-171 and SP 800-172
SP 800-171 requirements sourcing this control
SP 800-172 enhanced requirements sourcing this control
MITRE D3FEND techniques
MITRE ATT&CK relationships
Curated mitigation mappings
Inferred behavior relationships
Experimental: These relationships are inferred through D3FEND and must be validated against architecture, telemetry, and threat context.
Show 152 additional relationships
Use the map without overclaiming.
A CSF informative reference is not an equivalence statement. A source-control relationship is not proof of implementation. A D3FEND semantic relationship is not a product claim. An inferred ATT&CK link is a hypothesis for engineering analysis.
Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST or MITRE. Informative references and cross-framework relationships support navigation and analysis; they do not establish compliance, applicability, equivalence, control inheritance, or guaranteed mitigation effectiveness.