id: "IR-04(03)" title: "Continuity of Operations" family: "IR" family_name: "Incident Response" sort_id: "ir-04.03" priority: "P2" implementation_level: "organization" parent: "IR-04" enhancement: True


Statement

Identify {{ insert: param, ir-04.03_odp.01 }} and take the following actions in response to those incidents to ensure continuation of organizational mission and business functions: {{ insert: param, ir-04.03_odp.02 }}.

Guidance

Classes of incidents include malfunctions due to design or implementation errors and omissions, targeted malicious attacks, and untargeted malicious attacks. Incident response actions include orderly system degradation, system shutdown, fall back to manual mode or activation of alternative technology whereby the system operates differently, employing deceptive measures, alternate information flows, or operating in a mode that is reserved for when systems are under attack. Organizations consider whether continuity of operations requirements during an incident conflict with the capability to automatically disable the system as specified as part of IR-4(5).

Assessment Objective: {{ insert: param, ir-04.03_odp.01 }} are identified;

Assessment Objective: {{ insert: param, ir-04.03_odp.02 }} are taken in response to those incidents (defined in IR-04(03)_ODP[01]) to ensure the continuation of organizational mission and business functions.

Incident response policy

procedures addressing incident handling

incident response plan

privacy plan

list of classes of incidents

list of appropriate incident response actions

system security plan

other relevant documents or records

Organizational personnel with incident handling responsibilities

organizational personnel with information security responsibilities

Mechanisms that support and/or implement continuity of operations