RS.CO-02
Internal and external stakeholders are notified of incidents
Related NIST SP 800-53 controls
The imported relationship is superset-of with source confidence 100%. This is navigation evidence, not a claim that implementing the listed controls automatically achieves the outcome.
NIST SP 800-171 and SP 800-172
These requirements cite the mapped SP 800-53 controls or enhancements. Applicability still depends on the governing contract, agency selection, and system context.
SP 800-171 Rev. 3 requirements
SP 800-172 Rev. 3 enhanced requirements
MITRE D3FEND techniques
Semantic relationship labels and the exact SP 800-53 source reference are preserved from the imported D3FEND mapping.
MITRE ATT&CK relationships
Curated ATT&CK mitigation mappings
Inferred ATT&CK behavior relationships
Experimental: These links are inferred through shared D3FEND artifacts and relationships. They are not guarantees that a technique prevents or detects an ATT&CK behavior.
Show 152 additional relationships
Use the chain to ask better implementation questions.
- Which mapped controls are actually selected and implemented for this system?
- Which CUI requirements or enhanced requirements apply under the governing agreement?
- Which D3FEND techniques are implemented as real technical capabilities, and what evidence proves they operate?
- Which ATT&CK relationships are curated, and which are only inferred starting points for engineering analysis?
- What book, podcast, or Academy lesson gives the team enough depth to make a defensible decision?
Relationship provenance
NIST OLIR informative-reference record ↗ · NIST CSF 2.0 ↗
Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST or MITRE. Informative references and cross-framework relationships support navigation and analysis; they do not establish compliance, applicability, equivalence, control inheritance, or guaranteed mitigation effectiveness.