id: "IR-06" title: "Incident Reporting" family: "IR" family_name: "Incident Response" sort_id: "ir-06" priority: "P2" implementation_level: "organization" enhancements: - ir-6.1 - ir-6.2 - ir-6.3
Require personnel to report suspected incidents to the organizational incident response capability within {{ insert: param, ir-06_odp.01 }} ; and
Report incident information to {{ insert: param, ir-06_odp.02 }}.
Guidance
The types of incidents reported, the content and timeliness of the reports, and the designated reporting authorities reflect applicable laws, executive orders, directives, regulations, policies, standards, and guidelines. Incident information can inform risk assessments, control effectiveness assessments, security requirements for acquisitions, and selection criteria for technology products.
Assessment Objective: personnel is/are required to report suspected incidents to the organizational incident response capability within {{ insert: param, ir-06_odp.01 }};
Assessment Objective: incident information is reported to {{ insert: param, ir-06_odp.02 }}.
Incident response policy
procedures addressing incident reporting
incident reporting records and documentation
incident response plan
system security plan
privacy plan
other relevant documents or records
Organizational personnel with incident reporting responsibilities
organizational personnel with information security and privacy responsibilities
personnel who have/should have reported incidents
personnel (authorities) to whom incident information is to be reported
system users
Organizational processes for incident reporting
mechanisms supporting and/or implementing incident reporting