Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

NIST SP 800-172 Enhanced CUI Protection Center

03.06 — Incident Response

Study this CUI requirement family as a connected set of implementation decisions, evidence expectations, and assessment procedures.

4Active requirements
6Parameters
9Assessment objectives

CUI requirement family

Incident Response

Use this family as a planning boundary, but assess every applicable requirement against the real CUI system boundary, inherited services, organization-defined parameters, and operational evidence.

4 active0 withdrawnRevision 3
IR

Family catalog

Requirements and assessment procedures.

Withdrawn records remain available and link to the requirements where their intent was incorporated or addressed.

03.06.01EActive

Security Operations Center

A security operations center (SOC) is the focal point for security operations and computer network defense for an organization. The purpose of the SOC is to defend and monitor an organization’s systems and networks on an ongoing basis. The SOC is also responsible for detecting, analyzing, and responding to security incidents in a timely manner. The SOC is staffed with skilled technical and operational personnel (e.g.

03.06.02EActive

Integrated Incident Response Team

An integrated incident response team is a group of individuals who assess, document, and respond to incidents so that organizational systems and networks can recover quickly and implement the necessary controls to avoid future incidents. Incident response team personnel include forensic and malicious code analysts, tool developers, systems security engineers, and real-time operations personnel. The incident handling

03.06.03EActive

Behavior Analysis

If the organization maintains a deception environment, an analysis of behaviors in that environment, including resources targeted by the adversary and the timing of the incident or event, can provide significant insights into adversarial tactics, techniques, and procedures. External to a deception environment, the analysis of anomalous behavior (e.g., changes in system performance or usage patterns) or suspected adve