Control statement
- a.Develop an incident response plan that:
- 1.Provides the organization with a roadmap for implementing its incident response capability;
- 2.Describes the structure and organization of the incident response capability;
- 3.Provides a high-level approach for how the incident response capability fits into the overall organization;
- 4.Meets the unique requirements of the organization, which relate to mission, size, structure, and functions;
- 5.Defines reportable incidents;
- 6.Provides metrics for measuring the incident response capability within the organization;
- 7.Defines the resources and management support needed to effectively maintain and mature an incident response capability;
- 8.Addresses the sharing of incident information;
- 9.Is reviewed and approved by [Organization-defined: personnel or roles] [Organization-defined: frequency] ; and
- 10.Explicitly designates responsibility for incident response to [Organization-defined: entities, personnel, or roles].
- b.Distribute copies of the incident response plan to [Organization-defined: incident response personnel];
- c.Update the incident response plan to address system and organizational changes or problems encountered during plan implementation, execution, or testing;
- d.Communicate incident response plan changes to [Organization-defined: organization-defined incident response personnel (identified by name and/or by role) and organizational elements] ; and
- e.Protect the incident response plan from unauthorized disclosure and modification.
Discussion
It is important that organizations develop and implement a coordinated approach to incident response. Organizational mission and business functions determine the structure of incident response capabilities. As part of the incident response capabilities, organizations consider the coordination and sharing of information with external organizations, including external service providers and other organizations involved in the supply chain. For incidents involving personally identifiable information (i.e., breaches), include a process to determine whether notice to oversight organizations or affected individuals is appropriate and provide that notice accordingly.
Organization-defined parameters
These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.
From control text to operational evidence
Use Incident Response Plan as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to prepared detection, coordinated response, analysis, reporting, and lessons learned.
Implementation workflow
- Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
- Resolve each organization-defined parameter before declaring the control implemented.
- Document how the implementation satisfies every clause of the official control statement.
- Collect evidence as a normal byproduct of operation rather than only before an assessment.
- Review exceptions, changes, and monitoring results on a risk-based cadence.
Evidence examples
- incident response plans and playbooks
- case records and timelines
- exercise and tabletop results
- lessons-learned and corrective-action tracking
Common failure patterns
- plans that do not match current architecture
- unclear authority for containment decisions
- evidence lost during response
- lessons learned recorded but not implemented
Questions practitioners should ask
- What risk decision is this control intended to support in this system?
- Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
- Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
- What event or threshold requires the implementation to be reviewed or changed?
Assessment objectives and methods
Show the assessment objective
- IR-08a.
- IR-08a.01an incident response plan is developed that provides the organization with a roadmap for implementing its incident response capability;
- IR-08a.02an incident response plan is developed that describes the structure and organization of the incident response capability;
- IR-08a.03an incident response plan is developed that provides a high-level approach for how the incident response capability fits into the overall organization;
- IR-08a.04an incident response plan is developed that meets the unique requirements of the organization with regard to mission, size, structure, and functions;
- IR-08a.05an incident response plan is developed that defines reportable incidents;
- IR-08a.06an incident response plan is developed that provides metrics for measuring the incident response capability within the organization;
- IR-08a.07an incident response plan is developed that defines the resources and management support needed to effectively maintain and mature an incident response capability;
- IR-08a.08an incident response plan is developed that addresses the sharing of incident information;
- IR-08a.09an incident response plan is developed that is reviewed and approved by [Organization-defined: personnel or roles] [Organization-defined: frequency];
- IR-08a.10an incident response plan is developed that explicitly designates responsibility for incident response to [Organization-defined: entities, personnel, or roles].
- IR-08b.
- IR-08b.[01]copies of the incident response plan are distributed to [Organization-defined: incident response personnel];
- IR-08b.[02]copies of the incident response plan are distributed to [Organization-defined: organizational elements];
- IR-08c.the incident response plan is updated to address system and organizational changes or problems encountered during plan implementation, execution, or testing;
- IR-08d.
- IR-08d.[01]incident response plan changes are communicated to [Organization-defined: incident response personnel];
- IR-08d.[02]incident response plan changes are communicated to [Organization-defined: organizational elements];
- IR-08e.
- IR-08e.[01]the incident response plan is protected from unauthorized disclosure;
- IR-08e.[02]the incident response plan is protected from unauthorized modification.
Examine
- Incident response policy
- procedures addressing incident response planning
- incident response plan
- system security plan
- privacy plan
- records of incident response plan reviews and approvals
- other relevant documents or records
Interview
- Organizational personnel with incident response planning responsibilities
- organizational personnel with information security and privacy responsibilities
Test
- Organizational incident response plan and related organizational processes
Related controls
These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.
Control enhancements
Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.
IR-8(1) — Breaches
Include the following in the Incident Response Plan for breaches involving personally identifiable information:
- (a)A process to determine if notice to individuals or other organizations, including oversight organizations, is needed;
- (b)An assessment process to determine the extent of the harm, embarrassment, inconvenience, or unfairness to affected individuals and any mechanisms to mitigate such harms; and
- (c)Identification of applicable privacy requirements.
Official discussion
Organizations may be required by law, regulation, or policy to follow specific procedures relating to breaches, including notice to individuals, affected organizations, and oversight bodies; standards of harm; and mitigation or other specific requirements.
Assessment objectives and methods
- IR-08(01)(a)the incident response plan for breaches involving personally identifiable information includes a process to determine if notice to individuals or other organizations, including oversight organizations, is needed;
- IR-08(01)(b)the incident response plan for breaches involving personally identifiable information includes an assessment process to determine the extent of the harm, embarrassment, inconvenience, or unfairness to affected individuals and any mechanisms to mitigate such harms;
- IR-08(01)(c)the incident response plan for breaches involving personally identifiable information includes the identification of applicable privacy requirements.
Examine
- Incident response policy
- procedures addressing incident response planning
- incident response plan
- system security plan
- privacy plan
- records of incident response plan reviews and approvals
- other relevant documents or records
Interview
- Organizational personnel with incident response planning responsibilities
- organizational personnel with information security and privacy responsibilities
Test
- Organizational incident response plan and related organizational processes
Related controls
Authoritative sources
Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST. Official control requirements and interpretations remain with NIST and the responsible authorizing organization.