NIST800-IR-4 IR-4 Incident Handling
NIST800-IR-4 in NIST SP 800-53 Rev 5 (NIST SP 800-53 Rev 5, Release 5.2.0). All NIST SP 800-53 Rev 5 controls held. Open NIST SP 800-53 Rev 5 on the standards site.
The control as we hold it
IR-4 Incident Handling. a. Implement an incident handling capability for incidents that is consistent with the incident response plan and includes preparation, detection and analysis, containment, eradication, and recovery; b. Coordinate incident handling activities with contingency planning activities; c. Incorporate lessons learned from ongoing incident handling activities into incident response procedures, training, and testing, and implement the resulting changes accordingly; and d. Ensure the rigor, intensity, scope, and results of incident handling activities are comparable and predictable across the organization.
Reviewed and closest counterparts in the other frameworks
Reviewed rows come from a released pair; a closest match is the nearest held text and is not a reviewed row.
SOC 2
- SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16) (closest match)
- SOC2-CC6.8 CC6.8 Preventing and detecting unauthorised or malicious software (closest match)
- SOC2-CC7.3 CC7.3 Evaluating security events to identify incidents (closest match)
- SOC2-CC7.4 CC7.4 Responding to security incidents (closest match)
- SOC2-CC7.5 CC7.5 Recovering from security incidents (closest match)
- SOC2-P6.3 P6.3 Record of unauthorised disclosures and breaches (closest match)
- SOC2-P6.6 P6.6 Notifying breaches and incidents (closest match)
HIPAA Security Rule
- 164.308(a)(1)(i) Security Management Process (Standard) (closest match)
- 164.308(a)(5)(ii)(B) Protection from Malicious Software (Addressable) (closest match)
- 164.308(a)(6)(i) Security Incident Procedures (Standard) (closest match)
- 164.308(a)(6)(ii) Response and Reporting (Required) (closest match)
What an auditor commonly asks for
General guidance for this control area (domain: IR - Incident Response), in our words, not a statement of the standard and not binding on an assessor.
- the incident-response policy and plan
- the incident register with resolution
- the incident-response test records