Incident Reporting

✓ LOW ✓ MODERATE ✓ HIGH
3 Enhancements 1 Overlay 6 Related Controls
Graph
Export ▾

Requirements NIST SOURCE

Discussion (NIST Supplemental Guidance)

The types of incidents reported, the content and timeliness of the reports, and the designated reporting authorities reflect applicable laws, executive orders, directives, regulations, policies, standards, and guidelines. Incident information can inform risk assessments, control effectiveness assessments, security requirements for acquisitions, and selection criteria for technology products.

Enhancements NIST SOURCE

IR-6(1) Automated Reporting LOW ✓ MODERATE ✓ HIGH

Report incidents using [automated mechanisms].

Discussion

The recipients of incident reports are specified in IR-6b . Automated reporting mechanisms include email, posting on websites (with automatic updates), and automated incident response tools and programs.

Open full page for IR-6(1) →
IR-6(2) Vulnerabilities Related to Incidents LOW MODERATE HIGH

Report system vulnerabilities associated with reported incidents to [personnel or roles].

Discussion

Reported incidents that uncover system vulnerabilities are analyzed by organizational personnel including system owners, mission and business owners, senior agency information security officers, senior agency officials for privacy, authorizing officials, and the risk executive (function). The analysis can serve to prioritize and initiate mitigation actions to address the discovered system vulnerability.

Open full page for IR-6(2) →
IR-6(3) Supply Chain Coordination LOW ✓ MODERATE ✓ HIGH

Provide incident information to the provider of the product or service and other organizations involved in the supply chain or supply chain governance for systems or system components related to the incident.

Discussion

Organizations involved in supply chain activities include product developers, system integrators, manufacturers, packagers, assemblers, distributors, vendors, and resellers. Entities that provide supply chain governance include the Federal Acquisition Security Council (FASC). Supply chain incidents include compromises or breaches that involve information technology products, system components, development processes or personnel, distribution processes, or warehousing facilities. Organizations determine the appropriate information to share and consider the value gained from informing external organizations about supply chain incidents, including the ability to improve processes or to identify the root cause of an incident.

Open full page for IR-6(3) →

Implementation Guidance

Engineering Interpretation

Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.

No engineering interpretation has been authored for IR-6 yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.

Assessment

NIST SP 800-53A REV 5.2.0

Assessment Objectives

  1. time period for personnel to report suspected incidents to the organizational incident response capability is defined;
  2. authorities to whom incident information is to be reported are defined;
  3. personnel is/are required to report suspected incidents to the organizational incident response capability within <IR-06_ODP[01] time period>;
  4. incident information is reported to <IR-06_ODP[02] authorities>.

Examine

[SELECT FROM: Incident response policy; procedures addressing incident reporting; incident reporting records and documentation; incident response plan; system security plan; privacy plan; other relevant documents or records].

Interview

[SELECT FROM: Organizational personnel with incident reporting responsibilities; organizational personnel with information security and privacy responsibilities; personnel who have/should have reported incidents; personnel (authorities) to whom incident information is to be reported; system users].

Test

[SELECT FROM: Organizational processes for incident reporting; mechanisms supporting and/or implementing incident reporting].

Overlays

OT/ICS Overlay SP 800-82r3

NIST SP 800-82r3 Appendix F, Table 22. Blank baseline means the control/control enhancement is not selected in that initial OT baseline.

LOW

  • Base control: Included (matches standard baseline)

MODERATE

  • Base control: Included (matches standard baseline)
  • Included: (1) (3)

HIGH

  • Base control: Included (matches standard baseline)
  • Included: (1) (3)

STIGs & CCIs

No STIG checks or CCI mappings are currently loaded for IR-6. This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.

Learn more about STIG/CCI integration →

Evidence

Potential Evidence — Derived

Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.

Policy

  • Incident response policy
  • incident response plan
  • system security plan
  • privacy plan

Testing

  • Organizational processes for incident reporting
  • mechanisms supporting and/or implementing incident reporting

Other Records

  • procedures addressing incident reporting
  • incident reporting records and documentation
  • other relevant documents or records