id: "IR-04(05)" title: "Automatic Disabling of System" family: "IR" family_name: "Incident Response" sort_id: "ir-04.05" priority: "P2" implementation_level: "system" parent: "IR-04" enhancement: True


Statement

Implement a configurable capability to automatically disable the system if {{ insert: param, ir-04.05_odp }} are detected.

Guidance

Organizations consider whether the capability to automatically disable the system conflicts with continuity of operations requirements specified as part of CP-2 or IR-4(3) . Security violations include cyber-attacks that have compromised the integrity of the system or exfiltrated organizational information and serious errors in software programs that could adversely impact organizational missions or functions or jeopardize the safety of individuals.

Assessment Objective

a configurable capability is implemented to automatically disable the system if {{ insert: param, ir-04.05_odp }} are detected.

Incident response policy

procedures addressing incident handling

automated mechanisms supporting incident handling

system design documentation

system configuration settings and associated documentation

system security plan

incident response plan

privacy plan

other relevant documents or records

Organizational personnel with incident handling responsibilities

organizational personnel with information security responsibilities

system developers

Incident handling capability for the organization

automated mechanisms supporting and/or implementing automatic disabling of the system