Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

NIST SP 800-53 Learning Center

IR-8 — Incident Response Plan

Read the official control and assessment content, then use the separately labeled Bare Metal Cyber perspective to connect the requirement to implementation, evidence, and sustained operation.

1Enhancements
8Parameters
4Baseline memberships
3Assessment methods

IR — Incident Response · NIST SP 800-53 Release 5.2.0

LowModerateHighPrivacy
Official NIST control content

Control statement

  1. a.Develop an incident response plan that:
    1. 1.Provides the organization with a roadmap for implementing its incident response capability;
    2. 2.Describes the structure and organization of the incident response capability;
    3. 3.Provides a high-level approach for how the incident response capability fits into the overall organization;
    4. 4.Meets the unique requirements of the organization, which relate to mission, size, structure, and functions;
    5. 5.Defines reportable incidents;
    6. 6.Provides metrics for measuring the incident response capability within the organization;
    7. 7.Defines the resources and management support needed to effectively maintain and mature an incident response capability;
    8. 8.Addresses the sharing of incident information;
    9. 9.Is reviewed and approved by [Organization-defined: personnel or roles] [Organization-defined: frequency] ; and
    10. 10.Explicitly designates responsibility for incident response to [Organization-defined: entities, personnel, or roles].
  2. b.Distribute copies of the incident response plan to [Organization-defined: incident response personnel];
  3. c.Update the incident response plan to address system and organizational changes or problems encountered during plan implementation, execution, or testing;
  4. d.Communicate incident response plan changes to [Organization-defined: organization-defined incident response personnel (identified by name and/or by role) and organizational elements] ; and
  5. e.Protect the incident response plan from unauthorized disclosure and modification.
Official NIST discussion

Discussion

It is important that organizations develop and implement a coordinated approach to incident response. Organizational mission and business functions determine the structure of incident response capabilities. As part of the incident response capabilities, organizations consider the coordination and sharing of information with external organizations, including external service providers and other organizations involved in the supply chain. For incidents involving personally identifiable information (i.e., breaches), include a process to determine whether notice to oversight organizations or affected individuals is appropriate and provide that notice accordingly.

Official OSCAL parameters

Organization-defined parameters

These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.

organization-defined incident response personnel (identified by name and/or by role) and organizational elements
personnel or rolespersonnel or roles that review and approve the incident response plan is/are identified;
frequencythe frequency at which to review and approve the incident response plan is defined;
entities, personnel, or rolesentities, personnel, or roles with designated responsibility for incident response are defined;
incident response personnelincident response personnel (identified by name and/or by role) to whom copies of the incident response plan are to be distributed is/are defined;
organizational elementsorganizational elements to which copies of the incident response plan are to be distributed are defined;
incident response personnelincident response personnel (identified by name and/or by role) to whom changes to the incident response plan is/are communicated are defined;
organizational elementsorganizational elements to which changes to the incident response plan are communicated are defined;
Original Bare Metal Cyber perspective

From control text to operational evidence

Use Incident Response Plan as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to prepared detection, coordinated response, analysis, reporting, and lessons learned.

Implementation workflow

  • Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
  • Resolve each organization-defined parameter before declaring the control implemented.
  • Document how the implementation satisfies every clause of the official control statement.
  • Collect evidence as a normal byproduct of operation rather than only before an assessment.
  • Review exceptions, changes, and monitoring results on a risk-based cadence.

Evidence examples

  • incident response plans and playbooks
  • case records and timelines
  • exercise and tabletop results
  • lessons-learned and corrective-action tracking

Common failure patterns

  • plans that do not match current architecture
  • unclear authority for containment decisions
  • evidence lost during response
  • lessons learned recorded but not implemented

Questions practitioners should ask

  • What risk decision is this control intended to support in this system?
  • Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
  • Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
  • What event or threshold requires the implementation to be reviewed or changed?
Official NIST SP 800-53A content

Assessment objectives and methods

Show the assessment objective
  1. IR-08a.
    1. IR-08a.01an incident response plan is developed that provides the organization with a roadmap for implementing its incident response capability;
    2. IR-08a.02an incident response plan is developed that describes the structure and organization of the incident response capability;
    3. IR-08a.03an incident response plan is developed that provides a high-level approach for how the incident response capability fits into the overall organization;
    4. IR-08a.04an incident response plan is developed that meets the unique requirements of the organization with regard to mission, size, structure, and functions;
    5. IR-08a.05an incident response plan is developed that defines reportable incidents;
    6. IR-08a.06an incident response plan is developed that provides metrics for measuring the incident response capability within the organization;
    7. IR-08a.07an incident response plan is developed that defines the resources and management support needed to effectively maintain and mature an incident response capability;
    8. IR-08a.08an incident response plan is developed that addresses the sharing of incident information;
    9. IR-08a.09an incident response plan is developed that is reviewed and approved by [Organization-defined: personnel or roles] [Organization-defined: frequency];
    10. IR-08a.10an incident response plan is developed that explicitly designates responsibility for incident response to [Organization-defined: entities, personnel, or roles].
  2. IR-08b.
    1. IR-08b.[01]copies of the incident response plan are distributed to [Organization-defined: incident response personnel];
    2. IR-08b.[02]copies of the incident response plan are distributed to [Organization-defined: organizational elements];
  3. IR-08c.the incident response plan is updated to address system and organizational changes or problems encountered during plan implementation, execution, or testing;
  4. IR-08d.
    1. IR-08d.[01]incident response plan changes are communicated to [Organization-defined: incident response personnel];
    2. IR-08d.[02]incident response plan changes are communicated to [Organization-defined: organizational elements];
  5. IR-08e.
    1. IR-08e.[01]the incident response plan is protected from unauthorized disclosure;
    2. IR-08e.[02]the incident response plan is protected from unauthorized modification.

Examine

  • Incident response policy
  • procedures addressing incident response planning
  • incident response plan
  • system security plan
  • privacy plan
  • records of incident response plan reviews and approvals
  • other relevant documents or records

Interview

  • Organizational personnel with incident response planning responsibilities
  • organizational personnel with information security and privacy responsibilities

Test

  • Organizational incident response plan and related organizational processes
Official relationships

Related controls

These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.

Official NIST enhancements

Control enhancements

Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.

Official NIST control enhancement

IR-8(1) — Breaches

Privacy

Include the following in the Incident Response Plan for breaches involving personally identifiable information:

  1. (a)A process to determine if notice to individuals or other organizations, including oversight organizations, is needed;
  2. (b)An assessment process to determine the extent of the harm, embarrassment, inconvenience, or unfairness to affected individuals and any mechanisms to mitigate such harms; and
  3. (c)Identification of applicable privacy requirements.
Official discussion

Organizations may be required by law, regulation, or policy to follow specific procedures relating to breaches, including notice to individuals, affected organizations, and oversight bodies; standards of harm; and mitigation or other specific requirements.

Assessment objectives and methods
  1. IR-08(01)(a)the incident response plan for breaches involving personally identifiable information includes a process to determine if notice to individuals or other organizations, including oversight organizations, is needed;
  2. IR-08(01)(b)the incident response plan for breaches involving personally identifiable information includes an assessment process to determine the extent of the harm, embarrassment, inconvenience, or unfairness to affected individuals and any mechanisms to mitigate such harms;
  3. IR-08(01)(c)the incident response plan for breaches involving personally identifiable information includes the identification of applicable privacy requirements.

Examine

  • Incident response policy
  • procedures addressing incident response planning
  • incident response plan
  • system security plan
  • privacy plan
  • records of incident response plan reviews and approvals
  • other relevant documents or records

Interview

  • Organizational personnel with incident response planning responsibilities
  • organizational personnel with information security and privacy responsibilities

Test

  • Organizational incident response plan and related organizational processes
Related controls
Source record

Authoritative sources