RS.AN-06—Actions performed during an investigation are recorded, and the records’ integrity and provenance are preserved
>Control Description
This incident analysis subcategory ensures that actions performed during an investigation are recorded, and the records’ integrity and provenance are preserved. Key activities include: Require each incident responder and others (e; Require the incident lead to document the incident in detail and be responsible for preserving the integrity of the documentation and the sources o....
>Cross-Framework Mappings
>Informative References
Official NIST mappings to external frameworks and standards. Source: NIST CSF 2.0
CRI Profile v2.0
RS.AN-06
RS.AN-06.01
CSF v1.1
RS.AN-3
ISO/IEC 27001:2022
Mandatory Clause: None
Annex A Controls: 5.28
NICE Framework
IO-WRL-001
IO-WRL-002
IO-WRL-003
IO-WRL-006
PD-WRL-002
PD-WRL-003
PD-WRL-004
PCI DSS
10.3.2
10.3.1
10.3.3
10.3.4
10.6.1
10.5.1
SCF
IRO-02
IRO-08
IRO-09
SP 800-171 Rev 3
03.03.06
03.06.01
03.06.02
SP 800-53 Rev 5.1.1
AU-07
IR-04
IR-06
SP 800-53 Rev 5.2.0
AU-07
IR-04
IR-06
Ask AI
Configure your API key to use AI features.