Under active development Content is continuously updated and improved

IR-06Incident Reporting

Low
Moderate
Core Control

>Control Description

a

Require personnel to report suspected incidents to the organizational incident response capability within organization-defined time period; and

b

Report incident information to organization-defined authorities.

>Discussion

The types of incidents reported, the content and timeliness of the reports, and the designated reporting authorities reflect applicable laws, executive orders, directives, regulations, policies, standards, and guidelines. Incident information can inform risk assessments, control effectiveness assessments, security requirements for acquisitions, and selection criteria for technology products.

>Cross-Framework Mappings

Ask AI

Configure your API key to use AI features.