id: "IR-04(05)" title: "Automatic Disabling of System" family: "IR" family_name: "Incident Response" sort_id: "ir-04.05" priority: "P2" implementation_level: "system" parent: "IR-04" enhancement: True
Statement
Implement a configurable capability to automatically disable the system if {{ insert: param, ir-04.05_odp }} are detected.
Guidance
Organizations consider whether the capability to automatically disable the system conflicts with continuity of operations requirements specified as part of CP-2 or IR-4(3) . Security violations include cyber-attacks that have compromised the integrity of the system or exfiltrated organizational information and serious errors in software programs that could adversely impact organizational missions or functions or jeopardize the safety of individuals.
Assessment Objective
a configurable capability is implemented to automatically disable the system if {{ insert: param, ir-04.05_odp }} are detected.
Incident response policy
procedures addressing incident handling
automated mechanisms supporting incident handling
system design documentation
system configuration settings and associated documentation
system security plan
incident response plan
privacy plan
other relevant documents or records
Organizational personnel with incident handling responsibilities
organizational personnel with information security responsibilities
system developers
Incident handling capability for the organization
automated mechanisms supporting and/or implementing automatic disabling of the system