NIST800-IR-8 IR-8 Incident Response Plan
NIST800-IR-8 in NIST SP 800-53 Rev 5 (NIST SP 800-53 Rev 5, Release 5.2.0). All NIST SP 800-53 Rev 5 controls held. Open NIST SP 800-53 Rev 5 on the standards site.
The control as we hold it
IR-8 Incident Response Plan. a. Develop an incident response plan that: 1. Provides the organization with a roadmap for implementing its incident response capability; 2. Describes the structure and organization of the incident response capability; 3. Provides a high-level approach for how the incident response capability fits into the overall organization; 4. Meets the unique requirements of the organization, which relate to mission, size, structure, and functions; 5. Defines reportable incidents; 6. Provides metrics for measuring the incident response capability within the organization; 7. Defines the resources and management support needed to effectively maintain and mature an incident.
Reviewed and closest counterparts in the other frameworks
Reviewed rows come from a released pair; a closest match is the nearest held text and is not a reviewed row.
SOC 2
- SOC2-A1.3 A1.3 Testing recovery plan procedures (closest match)
- SOC2-CC7.3 CC7.3 Evaluating security events to identify incidents (closest match)
- SOC2-CC7.4 CC7.4 Responding to security incidents (closest match)
- SOC2-CC7.5 CC7.5 Recovering from security incidents (closest match)
- SOC2-CC9.1 CC9.1 Mitigating risks of business disruption (closest match)
- SOC2-P6.6 P6.6 Notifying breaches and incidents (closest match)
HIPAA Security Rule
- 164.308(a)(6)(i) Security Incident Procedures (Standard) (closest match)
- 164.308(a)(6)(ii) Response and Reporting (Required) (closest match)
What an auditor commonly asks for
General guidance for this control area (domain: IR - Incident Response), in our words, not a statement of the standard and not binding on an assessor.
- the incident-response policy and plan
- the incident register with resolution
- the incident-response test records