Doc:NIST SP 800-53Ar1 Appendix F/Enhanced/IR/Low

From FISMApedia
Jump to: navigation, search

NIST SP 800-53Ar1 Assessment Procedure Catalog, with SP 800-53r3 Security Controls


INCIDENT RESPONSE

IR-1 INCIDENT RESPONSE POLICY AND PROCEDURES


FAMILY: INCIDENT RESPONSE CLASS: OPERATIONAL


Security Control Baseline:
IR-1 Incident Response Policy and Procedures P1 LOW IR-1 MOD IR-1 HIGH IR-1


SECURITY CONTROL

Template:Doc:NIST SP 800-53r3 Appendix F/IR-1


ASSESSMENT PROCEDURE
IR-1 INCIDENT RESPONSE POLICY AND PROCEDURES
IR-1.1 ASSESSMENT OBJECTIVE:
Determine if:
(i) the organization develops and formally documents incident response policy;
(ii) the organization incident response policy addresses:
(iii) the organization disseminates formal documented incident response policy to elements within the organization having associated incident response roles and responsibilities;
(iv) the organization develops and formally documents incident response procedures;
(v) the organization incident response procedures facilitate implementation of the incident response policy and associated incident response controls; and
(vi) the organization disseminates formal documented incident response procedures to elements within the organization having associated incident response roles and responsibilities.
POTENTIAL ASSESSMENT METHODS AND OBJECTS:
Examine: [SELECT FROM: Incident response policy and procedures; other relevant documents or records].
Interview: [SELECT FROM: Organizational personnel with incident response responsibilities].
IR-1.2 ASSESSMENT OBJECTIVE:
Determine if:
(i) the organization defines the frequency of incident response policy reviews/updates;
(ii) the organization reviews/updates incident response policy in accordance with organization-defined frequency;
(iii) the organization defines the frequency of incident response procedure reviews/updates; and
(iv) the organization reviews/updates incident response procedures in accordance with organization-defined frequency.
POTENTIAL ASSESSMENT METHODS AND OBJECTS:
Examine: [SELECT FROM: Incident response policy and procedures; other relevant documents or records].
Interview: [SELECT FROM: Organizational personnel with incident response responsibilities].


IR-2 INCIDENT RESPONSE TRAINING


FAMILY: INCIDENT RESPONSE CLASS: OPERATIONAL


Security Control Baseline:
IR-2 Incident Response Training P2 LOW IR-2 MOD IR-2 HIGH IR-2 (1) (2)


SECURITY CONTROL

Template:Doc:NIST SP 800-53r3 Appendix F/IR-2


ASSESSMENT PROCEDURE
IR-2 INCIDENT RESPONSE TRAINING
IR-2.1 ASSESSMENT OBJECTIVE:
Determine if:
(i) the organization identifies personnel with incident response roles and responsibilities with respect to the information system;
(ii) the organization provides incident response training to personnel with incident response roles and responsibilities with respect to the information system;
(iii) incident response training material addresses the procedures and activities necessary to fulfill identified organizational incident response roles and responsibilities;
(iv) the organization defines the frequency of refresher incident response training; and
(v) the organization provides refresher incident response training in accordance with the organization-defined frequency.
POTENTIAL ASSESSMENT METHODS AND OBJECTS:
Examine: [SELECT FROM: Incident response policy; procedures addressing incident response training; incident response training material; security plan; incident response plan; incident response training records; other relevant documents or records].
Interview: [SELECT FROM: Organizational personnel with incident response training and operational responsibilities].



IR-4 INCIDENT HANDLING


FAMILY: INCIDENT RESPONSE CLASS: OPERATIONAL


Security Control Baseline:
IR-4 Incident Handling P1 LOW IR-4 MOD IR-4 (1) HIGH IR-4 (1)


SECURITY CONTROL

Template:Doc:NIST SP 800-53r3 Appendix F/IR-4


ASSESSMENT PROCEDURE
IR-4 INCIDENT HANDLING
IR-4.1 ASSESSMENT OBJECTIVE:
Determine if:
(i) the organization implements an incident handling capability for security incidents that includes:
  • preparation;
  • detection and analysis;
  • containment;
  • eradication; and
  • recovery;
(ii) the organization coordinates incident handling activities with contingency planning activities; and
(iii) the organization incorporates lessons learned from ongoing incident handling activities into:
  • incident response procedures;
  • training; and
  • testing/exercises; and
(iv) the organization implements the resulting changes to incident response procedures, training and testing/exercise accordingly.
POTENTIAL ASSESSMENT METHODS AND OBJECTS:
Examine: [SELECT FROM: Incident response policy; procedures addressing incident handling; incident response plan; other relevant documents or records].
Interview: [SELECT FROM: Organizational personnel with incident handling responsibilities; organizational personnel with contingency planning responsibilities].
Test: [SELECT FROM: Incident handling capability for the organization].


IR-5 INCIDENT MONITORING


FAMILY: INCIDENT RESPONSE CLASS: OPERATIONAL


Security Control Baseline:
IR-5 Incident Monitoring P1 LOW IR-5 MOD IR-5 HIGH IR-5 (1)


SECURITY CONTROL

Template:Doc:NIST SP 800-53r3 Appendix F/IR-5


ASSESSMENT PROCEDURE
IR-5 INCIDENT MONITORING
IR-5.1 ASSESSMENT OBJECTIVE:
Determine if the organization tracks and documents information system security incidents.
POTENTIAL ASSESSMENT METHODS AND OBJECTS:
Examine: [SELECT FROM: Incident response policy; procedures addressing incident monitoring; incident response records and documentation; incident response plan; other relevant documents or records].
Interview: [SELECT FROM: Organizational personnel with incident monitoring responsibilities].
Test: [SELECT FROM: Incident monitoring capability for the organization].


IR-6 INCIDENT REPORTING


FAMILY: INCIDENT RESPONSE CLASS: OPERATIONAL


Security Control Baseline:
IR-6 Incident Reporting P1 LOW IR-6 MOD IR-6 (1) HIGH IR-6 (1)


SECURITY CONTROL

Template:Doc:NIST SP 800-53r3 Appendix F/IR-6


ASSESSMENT PROCEDURE
IR-6 INCIDENT REPORTING
IR-6.1 ASSESSMENT OBJECTIVE:
Determine if:
(i) the organization defines in the time period required to report suspected security incidents to the organizational incident response capability;
(ii) the organization requires personnel to report suspected security incidents to the organizational incident response capability within the organization-defined time period; and
(iii) the organization reports security incident information to designated authorities.
POTENTIAL ASSESSMENT METHODS AND OBJECTS:
Examine: [SELECT FROM: Incident response policy; procedures addressing incident reporting; incident reporting records and documentation; security plan; incident response plan; other relevant documents or records].
Interview: [SELECT FROM: Organizational personnel with incident reporting responsibilities].



IR-7 INCIDENT RESPONSE ASSISTANCE


FAMILY: INCIDENT RESPONSE CLASS: OPERATIONAL


Security Control Baseline:
IR-7 Incident Response Assistance P3 LOW IR-7 MOD IR-7 (1) HIGH IR-7 (1)


SECURITY CONTROL

Template:Doc:NIST SP 800-53r3 Appendix F/IR-7


ASSESSMENT PROCEDURE
IR-7 INCIDENT RESPONSE ASSISTANCE
IR-7.1 ASSESSMENT OBJECTIVE:
Determine if:
(i) the organization provides an incident response support resource that offers advice and assistance to users of the information system for the handling and reporting of security incidents; and
(ii) the incident response support resource is an integral part of the organization's incident response capability.
POTENTIAL ASSESSMENT METHODS AND OBJECTS:
Examine: [SELECT FROM: Incident response policy; procedures addressing incident response assistance; incident response plan; other relevant documents or records].
Interview: [SELECT FROM: Organizational personnel with incident response assistance and support responsibilities].



IR-8 INCIDENT RESPONSE PLAN


FAMILY: INCIDENT RESPONSE CLASS: OPERATIONAL


Security Control Baseline:
IR-8 Incident Response Plan P1 LOW IR-8 MOD IR-8 HIGH IR-8


SECURITY CONTROL

Template:Doc:NIST SP 800-53r3 Appendix F/IR-8


ASSESSMENT PROCEDURE
IR-8 INCIDENT RESPONSE PLAN
IR-8.1 ASSESSMENT OBJECTIVE:
Determine if the organization develops an incident response plan that:
  • provides the organization with a roadmap for implementing its incident response capability;
  • describes the structure and organization of the incident response capability;
  • provides a high-level approach for how the incident response capability fits into the overall organization;
  • meets the unique requirements of the organization, which relate to mission, size, structure, and functions;
  • defines reportable incidents;
  • provides metrics for measuring the incident response capability within the organization;
  • defines the resources and management support needed to effectively maintain and mature an incident response capability; and
  • is reviewed and approved by designated officials within the organization.
POTENTIAL ASSESSMENT METHODS AND OBJECTS:
Examine: [SELECT FROM: Incident response policy; procedures addressing incident response assistance; incident response plan; other relevant documents or records].
Interview: [SELECT FROM: Organizational personnel with incident response planning responsibilities].
IR-8.2 ASSESSMENT OBJECTIVE:
Determine if:
(i) the organization defines, in the incident response plan, incident response personnel (identified by name and/or role) and organizational elements;
(ii) the organization distributes copies of the incident response plan to incident response personnel and organizational elements identified in the plan;
(iii) the organization defines, in the incident response plan, the frequency to review the plan;
(iv) the organization reviews the incident response plan in accordance with the organization-defined frequency;
(v) the organization revises the incident response plan to address system/organizational changes or problems encountered during plan implementation, execution, or testing; and
(vi) the organization communicates incident response plan changes to incident response personnel and organizational elements identified in the plan.
POTENTIAL ASSESSMENT METHODS AND OBJECTS:
Examine: [SELECT FROM: Incident response policy; procedures addressing incident response assistance; incident response plan; other relevant documents or records].
Interview: [SELECT FROM: Organizational personnel with incident response planning responsibilities].


Source