Incident data and metadata are collected, and their integrity and provenance are preserved
| Publié par | NIST |
|---|---|
| Version | 2.0 |
| Date de publication | 2024-02-26 |
| Langue | en |
| Exigences | 225 |
| Document source | csf.xlsx |
| Clé de plateforme | arcate:compliance:frameworks/nist-csf/2.0 |
Exigences
An incident's magnitude is estimated and validated
RS.CO
— Incident Response Reporting and Communication
Response activities are coordinated with internal and external stakeholders as required by laws, regulations, or policies
[Withdrawn: Incorporated into PR.AT-01]
Internal and external stakeholders are notified of incidents
Information is shared with designated internal and external stakeholders
[Withdrawn: Incorporated into RS.MA-01, RS.MA-04]
[Withdrawn: Incorporated into RS.CO-03]
RS.MI
— Incident Mitigation
Activities are performed to prevent expansion of an event and mitigate its effects
Incidents are contained
Incidents are eradicated
[Withdrawn: Incorporated into ID.RA-06]
RS.RP
— Response Planning
[Withdrawn: Incorporated into RS.MA]
[Withdrawn: Incorporated into RS.MA-01]
RS.IM
— Improvements
[Withdrawn: Incorporated into ID.IM]
[Withdrawn: Incorporated into ID.IM-03, ID.IM-04]
[Withdrawn: Incorporated into ID.IM-03]
RC
— RECOVER
Assets and operations affected by a cybersecurity incident are restored
RC.RP
— Incident Recovery Plan Execution
Restoration activities are performed to ensure operational availability of systems and services affected by cybersecurity incidents
The recovery portion of the incident response plan is executed once initiated from the incident response process
Recovery actions are selected, scoped, prioritized, and performed
The integrity of backups and other restoration assets is verified before using them for restoration
Critical mission functions and cybersecurity risk management are considered to establish post-incident operational norms
The integrity of restored assets is verified, systems and services are restored, and normal operating status is confirmed