id: "IR-06" title: "Incident Reporting" family: "IR" family_name: "Incident Response" sort_id: "ir-06" priority: "P2" implementation_level: "organization" enhancements: - ir-6.1 - ir-6.2 - ir-6.3


Require personnel to report suspected incidents to the organizational incident response capability within {{ insert: param, ir-06_odp.01 }} ; and

Report incident information to {{ insert: param, ir-06_odp.02 }}.

Guidance

The types of incidents reported, the content and timeliness of the reports, and the designated reporting authorities reflect applicable laws, executive orders, directives, regulations, policies, standards, and guidelines. Incident information can inform risk assessments, control effectiveness assessments, security requirements for acquisitions, and selection criteria for technology products.

Assessment Objective: personnel is/are required to report suspected incidents to the organizational incident response capability within {{ insert: param, ir-06_odp.01 }};

Assessment Objective: incident information is reported to {{ insert: param, ir-06_odp.02 }}.

Incident response policy

procedures addressing incident reporting

incident reporting records and documentation

incident response plan

system security plan

privacy plan

other relevant documents or records

Organizational personnel with incident reporting responsibilities

organizational personnel with information security and privacy responsibilities

personnel who have/should have reported incidents

personnel (authorities) to whom incident information is to be reported

system users

Organizational processes for incident reporting

mechanisms supporting and/or implementing incident reporting