id: "IR-04(02)" title: "Dynamic Reconfiguration" family: "IR" family_name: "Incident Response" sort_id: "ir-04.02" priority: "P2" implementation_level: "organization" parent: "IR-04" enhancement: True


Statement

Include the following types of dynamic reconfiguration for {{ insert: param, ir-04.02_odp.02 }} as part of the incident response capability: {{ insert: param, ir-04.02_odp.01 }}.

Guidance

Dynamic reconfiguration includes changes to router rules, access control lists, intrusion detection or prevention system parameters, and filter rules for guards or firewalls. Organizations may perform dynamic reconfiguration of systems to stop attacks, misdirect attackers, and isolate components of systems, thus limiting the extent of the damage from breaches or compromises. Organizations include specific time frames for achieving the reconfiguration of systems in the definition of the reconfiguration capability, considering the potential need for rapid response to effectively address cyber threats.

Assessment Objective

{{ insert: param, ir-04.02_odp.01 }} for {{ insert: param, ir-04.02_odp.02 }} are included as part of the incident response capability.

Incident response policy

procedures addressing incident handling

mechanisms supporting incident handling

list of system components to be dynamically reconfigured as part of incident response capability

system design documentation

system configuration settings and associated documentation

system audit records

incident response plan

system security plan

other relevant documents or records

Organizational personnel with incident handling responsibilities

organizational personnel with information security responsibilities

Mechanisms that support and/or implement the dynamic reconfiguration of components as part of incident response