Policy and Procedures IR-1
Incident Response · Low baseline ✗ Not implemented
Status — program-wide
What references this control
No risks name this control in their Framework field yet.
No policies reference it yet.
Link a risk or policy to this control
Attaching adds IR-1 to the item's Framework field; the ✨ AI button suggests the best match. You can also edit the Framework field on a risk / policy directly.
Source: NIST SP 800-53 Rev.5, Incident Response family NIST SP 800-53 Rev.5. The baseline shows the lowest SP 800-53B baseline (Low / Moderate / High) this control appears in NIST SP 800-53B.
Control guide — plain-English, per NIST SP 800-53
IR-1 (Policy and Procedures) is the paperwork that the rest of Incident Response stands on: a written incident response policy that says why the program exists, who owns it, and how far it reaches, plus the step-by-step procedures that put the policy into practice. It names an official to keep both current and sets a schedule to review and update them. It is a Low-baseline control, so it applies from the very start.
What good looks like
- Have a written incident response policy that covers purpose, scope, roles, responsibilities, and management commitment — not just a folder of scattered notes.
- Name one official who owns the policy and procedures and is responsible for keeping them current.
- Back the policy with procedures that spell out how incidents are detected, reported, handled, and closed on this server.
- Make sure the policy is consistent with the laws and rules you fall under, and that the people who need it have actually seen it.
- Review and update the policy and procedures on a set schedule (for example, yearly) and after any major change or real incident.
Framework mapping
- NIST CSF 2.0 — GV.PO-01 — Policy for managing cybersecurity risks is established and communicated
- CIS Controls v8 — Control 17 — Incident Response Management
How to move it toward Implemented
- Write a one-page incident response policy: purpose, scope, the roles involved, and who signs off — save it where the team can find it.
- Write short procedures that match this Linux server: where the logs live (
/var/log,journalctl), how to report an incident, and who to call. - Name the responsible official in the document and set a review date (for example, every 12 months or after any incident).
- Attach the signed policy and procedures as hardening evidence on the asset, naming
IR-1in the Requirement field — that moves it from ‘To assess’ toward ‘Completed’.