Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

NIST SP 800-171 CUI Protection Center

03.06 — Incident Response

Study this CUI requirement family as a connected set of implementation decisions, evidence expectations, and assessment procedures.

5Active requirements
7Parameters
29Assessment objectives

CUI requirement family

Incident Response

Use this family as a planning boundary, but assess every applicable requirement against the real CUI system boundary, inherited services, organization-defined parameters, and operational evidence.

5 active0 withdrawnRevision 3
IR

Family catalog

Requirements and assessment procedures.

Withdrawn records remain available and link to the requirements where their intent was incorporated or addressed.

03.06.01Active

Incident Handling

Incident-related information can be obtained from a variety of sources, including audit monitoring, network monitoring, physical access monitoring, user and administrator reports, and reported supply chain events. An effective incident handling capability involves coordination among many organizational entities, including mission and business owners, system owners, human resources offices, physical and personnel secu

03.06.02Active

Incident Monitoring, Reporting, and Response Assistance

Documenting incidents includes maintaining records about each incident, the status of the incident, and other pertinent information necessary for forensics as well as evaluating incident details, trends, and handling. Incident information can be obtained from many sources, including network monitoring, incident reports, incident response teams, user complaints, supply chain partners, audit monitoring, physical access

03.06.03Active

Incident Response Testing

Organizations test incident response capabilities to determine their effectiveness and identify potential weaknesses or deficiencies. Incident response testing includes the use of checklists, walk-through or tabletop exercises, and simulations. Incident response testing can include a determination of the effects of incident response on organizational operations, organizational assets, and individuals. Qualitative and

03.06.04Active

Incident Response Training

Incident response training is associated with the assigned roles and responsibilities of organizational personnel to ensure that the appropriate content and level of detail are included in such training. For example, users may only need to know how to recognize an incident or whom to call; system administrators may require additional training on how to handle incidents; and incident responders may receive specific tr

03.06.05Active

Incident Response Plan

It is important that organizations develop and implement a coordinated approach to incident response. Organizational mission and business functions determine the structure of incident response capabilities. As part of the incident response capabilities, organizations consider the coordination and sharing of information with external organizations, including external service providers and other organizations involved