Under active development Content is continuously updated and improved

RS.AN-06Actions performed during an investigation are recorded, and the records’ integrity and provenance are preserved

>Control Description

This incident analysis subcategory ensures that actions performed during an investigation are recorded, and the records’ integrity and provenance are preserved. Key activities include: Require each incident responder and others (e; Require the incident lead to document the incident in detail and be responsible for preserving the integrity of the documentation and the sources o....

>Cross-Framework Mappings

>Informative References

Official NIST mappings to external frameworks and standards. Source: NIST CSF 2.0

CRI Profile v2.0

RS.AN-06
RS.AN-06.01

CSF v1.1

RS.AN-3

ISO/IEC 27001:2022

Mandatory Clause: None
Annex A Controls: 5.28

NICE Framework

IO-WRL-001
IO-WRL-002
IO-WRL-003
IO-WRL-006
PD-WRL-002
PD-WRL-003
PD-WRL-004

PCI DSS

10.3.2
10.3.1
10.3.3
10.3.4
10.6.1
10.5.1

SCF

IRO-02
IRO-08
IRO-09

SP 800-171 Rev 3

03.03.06
03.06.01
03.06.02

SP 800-53 Rev 5.1.1

AU-07
IR-04
IR-06

SP 800-53 Rev 5.2.0

AU-07
IR-04
IR-06

Ask AI

Configure your API key to use AI features.