home || catalog: SP800-53rev3 / class: Operational / family: (IR) Incident Response ||
search controls:
search nistpubs:

AC
AT
AU
CA
CM
CP
IA
IR

IR-01
IR-02
IR-03
IR-04
IR-05
IR-06 *
IR-07
IR-08

MA
MP
PE
PL
PM
PS
RA
SA
SC
SI
MMMMM

  IR-06: Incident Reporting  

base control objective:
The organization:
a. Requires personnel to report suspected security incidents to the organizational incident response capability within [Assignment: organization-defined time-period]; and
b. Reports security incident information to designated authorities.

supplemental objective information:
The intent of this control is to address both specific incident reporting requirements within an organization and the formal incident reporting requirements for federal agencies and their subordinate organizations. The types of security incidents reported, the content and timeliness of the reports, and the list of designated reporting authorities are consistent with applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidance. Current federal policy requires that all federal agencies (unless specifically exempted from such requirements), report security incidents to the United States Computer Emergency Readiness Team (US-CERT) within specified timeframes designated in the US-CERT Concept of Operations for Federal Cyber Security Incident Handling.

enhancements to the base objective:

(1) The organization employs automated mechanisms to assist in the reporting of security incidents.

(2) The organization reports information system weaknesses, deficiencies, and/or vulnerabilities associated with reported security incidents to appropriate organizational officials.

mapping to FIPS199 baseline:

  LOW: base     MOD: base (1)     HIGH: base (1)  

related (regimented) controls:

IR-04   Incident Handling
IR-05   Incident Monitoring

documents referenced in SP800-53rev3 for IR-06:

Document Date Status Title
NIST SP800-61 August, 2012 current   Computer Security Incident Handling Guide

Search SP800-53rev3 catalog: