NIST SP 800-53Ar1 Assessment Procedure Catalog, with SP 800-53r3 Security Controls
INCIDENT RESPONSE
IR-1 INCIDENT RESPONSE POLICY AND PROCEDURES
FAMILY: INCIDENT RESPONSE
|
CLASS: OPERATIONAL
|
- Security Control Baseline:
IR-1
|
Incident Response Policy and Procedures
|
P1
|
LOW IR-1
|
MOD IR-1
|
HIGH IR-1
|
ASSESSMENT PROCEDURE
|
IR-1 |
INCIDENT RESPONSE POLICY AND PROCEDURES
|
IR-1.1 |
ASSESSMENT OBJECTIVE:
Determine if:
- (i) the organization develops and formally documents incident response policy;
- (ii) the organization incident response policy addresses:
- (iii) the organization disseminates formal documented incident response policy to elements within the organization having associated incident response roles and responsibilities;
- (iv) the organization develops and formally documents incident response procedures;
- (v) the organization incident response procedures facilitate implementation of the incident response policy and associated incident response controls; and
- (vi) the organization disseminates formal documented incident response procedures to elements within the organization having associated incident response roles and responsibilities.
|
- POTENTIAL ASSESSMENT METHODS AND OBJECTS:
- Examine: [SELECT FROM: Incident response policy and procedures; other relevant documents or records].
- Interview: [SELECT FROM: Organizational personnel with incident response responsibilities].
|
IR-1.2 |
ASSESSMENT OBJECTIVE:
Determine if:
- (i) the organization defines the frequency of incident response policy reviews/updates;
- (ii) the organization reviews/updates incident response policy in accordance with organization-defined frequency;
- (iii) the organization defines the frequency of incident response procedure reviews/updates; and
- (iv) the organization reviews/updates incident response procedures in accordance with organization-defined frequency.
|
- POTENTIAL ASSESSMENT METHODS AND OBJECTS:
- Examine: [SELECT FROM: Incident response policy and procedures; other relevant documents or records].
- Interview: [SELECT FROM: Organizational personnel with incident response responsibilities].
|
IR-2 INCIDENT RESPONSE TRAINING
FAMILY: INCIDENT RESPONSE
|
CLASS: OPERATIONAL
|
- Security Control Baseline:
IR-2
|
Incident Response Training
|
P2
|
LOW IR-2
|
MOD IR-2
|
HIGH IR-2 (1) (2)
|
ASSESSMENT PROCEDURE
|
IR-2 |
INCIDENT RESPONSE TRAINING
|
IR-2.1 |
ASSESSMENT OBJECTIVE:
Determine if:
- (i) the organization identifies personnel with incident response roles and responsibilities with respect to the information system;
- (ii) the organization provides incident response training to personnel with incident response roles and responsibilities with respect to the information system;
- (iii) incident response training material addresses the procedures and activities necessary to fulfill identified organizational incident response roles and responsibilities;
- (iv) the organization defines the frequency of refresher incident response training; and
- (v) the organization provides refresher incident response training in accordance with the organization-defined frequency.
|
- POTENTIAL ASSESSMENT METHODS AND OBJECTS:
- Examine: [SELECT FROM: Incident response policy; procedures addressing incident response training; incident response training material; security plan; incident response plan; incident response training records; other relevant documents or records].
- Interview: [SELECT FROM: Organizational personnel with incident response training and operational responsibilities].
|
IR-3 INCIDENT RESPONSE TESTING AND EXERCISES
FAMILY: INCIDENT RESPONSE
|
CLASS: OPERATIONAL
|
- Security Control Baseline:
IR-3
|
Incident Response Testing and Exercises
|
P2
|
LOW Not Selected
|
MOD IR-3
|
HIGH IR-3 (1)
|
ASSESSMENT PROCEDURE
|
IR-3 |
INCIDENT RESPONSE TESTING AND EXERCISES
|
IR-3.1 |
ASSESSMENT OBJECTIVE:
Determine if:
- (i) the organization defines incident response tests/exercises;
- (ii) the organization defines the frequency of incident response tests/exercises;
- (iii) the organization tests/exercises the incident response capability for the information system using organization-defined tests/exercises in accordance with organization-defined frequency;
- (iv) the organization documents the results of incident response tests/exercises; and
- (v) the organization determines the effectiveness of the incident response capability.
|
- POTENTIAL ASSESSMENT METHODS AND OBJECTS:
- Examine: [SELECT FROM: Incident response policy; procedures addressing incident response testing and exercises; security plan; incident response testing material; incident response test results; incident response plan; other relevant documents or records].
- Interview: [SELECT FROM: Organizational personnel with incident response testing responsibilities].
|
IR-4 INCIDENT HANDLING
FAMILY: INCIDENT RESPONSE
|
CLASS: OPERATIONAL
|
- Security Control Baseline:
IR-4
|
Incident Handling
|
P1
|
LOW IR-4
|
MOD IR-4 (1)
|
HIGH IR-4 (1)
|
ASSESSMENT PROCEDURE
|
IR-4 |
INCIDENT HANDLING
|
IR-4.1 |
ASSESSMENT OBJECTIVE:
Determine if:
- (i) the organization implements an incident handling capability for security incidents that includes:
- preparation;
- detection and analysis;
- containment;
- eradication; and
- recovery;
- (ii) the organization coordinates incident handling activities with contingency planning activities; and
- (iii) the organization incorporates lessons learned from ongoing incident handling activities into:
- incident response procedures;
- training; and
- testing/exercises; and
- (iv) the organization implements the resulting changes to incident response procedures, training and testing/exercise accordingly.
|
- POTENTIAL ASSESSMENT METHODS AND OBJECTS:
- Examine: [SELECT FROM: Incident response policy; procedures addressing incident handling; incident response plan; other relevant documents or records].
- Interview: [SELECT FROM: Organizational personnel with incident handling responsibilities; organizational personnel with contingency planning responsibilities].
- Test: [SELECT FROM: Incident handling capability for the organization].
|
IR-4(1) |
INCIDENT HANDLING
|
IR-4(1).1 |
ASSESSMENT OBJECTIVE:
Determine if the organization employs automated mechanisms to support the incident handling process.
|
- POTENTIAL ASSESSMENT METHODS AND OBJECTS:
- Examine: [SELECT FROM: Incident response policy; procedures addressing incident handling; automated mechanisms supporting incident handling; other relevant documents or records].
- Interview: [SELECT FROM: Organizational personnel with incident handling responsibilities].
|
IR-5 INCIDENT MONITORING
FAMILY: INCIDENT RESPONSE
|
CLASS: OPERATIONAL
|
- Security Control Baseline:
IR-5
|
Incident Monitoring
|
P1
|
LOW IR-5
|
MOD IR-5
|
HIGH IR-5 (1)
|
ASSESSMENT PROCEDURE
|
IR-5 |
INCIDENT MONITORING
|
IR-5.1 |
ASSESSMENT OBJECTIVE:
Determine if the organization tracks and documents information system security incidents.
|
- POTENTIAL ASSESSMENT METHODS AND OBJECTS:
- Examine: [SELECT FROM: Incident response policy; procedures addressing incident monitoring; incident response records and documentation; incident response plan; other relevant documents or records].
- Interview: [SELECT FROM: Organizational personnel with incident monitoring responsibilities].
- Test: [SELECT FROM: Incident monitoring capability for the organization].
|
IR-6 INCIDENT REPORTING
FAMILY: INCIDENT RESPONSE
|
CLASS: OPERATIONAL
|
- Security Control Baseline:
IR-6
|
Incident Reporting
|
P1
|
LOW IR-6
|
MOD IR-6 (1)
|
HIGH IR-6 (1)
|
ASSESSMENT PROCEDURE
|
IR-6 |
INCIDENT REPORTING
|
IR-6.1 |
ASSESSMENT OBJECTIVE:
Determine if:
- (i) the organization defines in the time period required to report suspected security incidents to the organizational incident response capability;
- (ii) the organization requires personnel to report suspected security incidents to the organizational incident response capability within the organization-defined time period; and
- (iii) the organization reports security incident information to designated authorities.
|
- POTENTIAL ASSESSMENT METHODS AND OBJECTS:
- Examine: [SELECT FROM: Incident response policy; procedures addressing incident reporting; incident reporting records and documentation; security plan; incident response plan; other relevant documents or records].
- Interview: [SELECT FROM: Organizational personnel with incident reporting responsibilities].
|
IR-6(1) |
INCIDENT REPORTING
|
IR-6(1).1 |
ASSESSMENT OBJECTIVE:
Determine if the organization employs automated mechanisms to assist in the reporting of security incidents.
|
- POTENTIAL ASSESSMENT METHODS AND OBJECTS:
- Examine: [SELECT FROM: Incident response policy; procedures addressing incident reporting; automated mechanisms supporting incident reporting; incident response plan; other relevant documents or records].
- Interview: [SELECT FROM: Organizational personnel with incident reporting responsibilities].
|
IR-7 INCIDENT RESPONSE ASSISTANCE
FAMILY: INCIDENT RESPONSE
|
CLASS: OPERATIONAL
|
- Security Control Baseline:
IR-7
|
Incident Response Assistance
|
P3
|
LOW IR-7
|
MOD IR-7 (1)
|
HIGH IR-7 (1)
|
ASSESSMENT PROCEDURE
|
IR-7 |
INCIDENT RESPONSE ASSISTANCE
|
IR-7.1 |
ASSESSMENT OBJECTIVE:
Determine if:
- (i) the organization provides an incident response support resource that offers advice and assistance to users of the information system for the handling and reporting of security incidents; and
- (ii) the incident response support resource is an integral part of the organization's incident response capability.
|
- POTENTIAL ASSESSMENT METHODS AND OBJECTS:
- Examine: [SELECT FROM: Incident response policy; procedures addressing incident response assistance; incident response plan; other relevant documents or records].
- Interview: [SELECT FROM: Organizational personnel with incident response assistance and support responsibilities].
|
IR-7(1) |
INCIDENT RESPONSE ASSISTANCE
|
IR-7(1).1 |
ASSESSMENT OBJECTIVE:
Determine if the organization employs automated mechanisms to increase the availability of incident response-related information and support.
|
- POTENTIAL ASSESSMENT METHODS AND OBJECTS:
- Examine: [SELECT FROM: Incident response policy; procedures addressing incident response assistance; automated mechanisms supporting incident response support and assistance; incident response plan; other relevant documents or records].
- Interview: [SELECT FROM: Organizational personnel with incident response support and assistance responsibilities; organizational personnel that require incident response support and assistance].
|
IR-8 INCIDENT RESPONSE PLAN
FAMILY: INCIDENT RESPONSE
|
CLASS: OPERATIONAL
|
- Security Control Baseline:
IR-8
|
Incident Response Plan
|
P1
|
LOW IR-8
|
MOD IR-8
|
HIGH IR-8
|
ASSESSMENT PROCEDURE
|
IR-8 |
INCIDENT RESPONSE PLAN
|
IR-8.1 |
ASSESSMENT OBJECTIVE:
Determine if the organization develops an incident response plan that:
- provides the organization with a roadmap for implementing its incident response capability;
- describes the structure and organization of the incident response capability;
- provides a high-level approach for how the incident response capability fits into the overall organization;
- meets the unique requirements of the organization, which relate to mission, size, structure, and functions;
- defines reportable incidents;
- provides metrics for measuring the incident response capability within the organization;
- defines the resources and management support needed to effectively maintain and mature an incident response capability; and
- is reviewed and approved by designated officials within the organization.
|
- POTENTIAL ASSESSMENT METHODS AND OBJECTS:
- Examine: [SELECT FROM: Incident response policy; procedures addressing incident response assistance; incident response plan; other relevant documents or records].
- Interview: [SELECT FROM: Organizational personnel with incident response planning responsibilities].
|
IR-8.2 |
ASSESSMENT OBJECTIVE:
Determine if:
- (i) the organization defines, in the incident response plan, incident response personnel (identified by name and/or role) and organizational elements;
- (ii) the organization distributes copies of the incident response plan to incident response personnel and organizational elements identified in the plan;
- (iii) the organization defines, in the incident response plan, the frequency to review the plan;
- (iv) the organization reviews the incident response plan in accordance with the organization-defined frequency;
- (v) the organization revises the incident response plan to address system/organizational changes or problems encountered during plan implementation, execution, or testing; and
- (vi) the organization communicates incident response plan changes to incident response personnel and organizational elements identified in the plan.
|
- POTENTIAL ASSESSMENT METHODS AND OBJECTS:
- Examine: [SELECT FROM: Incident response policy; procedures addressing incident response assistance; incident response plan; other relevant documents or records].
- Interview: [SELECT FROM: Organizational personnel with incident response planning responsibilities].
|
Source