Incident Response Plan IR-8
Incident Response · Low baseline ✗ Not implemented
Status — program-wide
What references this control
No risks name this control in their Framework field yet.
No policies reference it yet.
Link a risk or policy to this control
Attaching adds IR-8 to the item's Framework field; the ✨ AI button suggests the best match. You can also edit the Framework field on a risk / policy directly.
Source: NIST SP 800-53 Rev.5, Incident Response family NIST SP 800-53 Rev.5. The baseline shows the lowest SP 800-53B baseline (Low / Moderate / High) this control appears in NIST SP 800-53B.
Control guide — plain-English, per NIST SP 800-53
IR-8 (Incident Response Plan) requires a written, approved plan: the roadmap and structure of the incident-response capability, roles and responsibilities, how incidents are reported and handled, success metrics, and a schedule to review and update it. The approved plan is distributed to the people who carry it out.
What good looks like
- Document the capability: purpose, scope, the handling phases, and clear roles and responsibilities.
- Define how incidents are reported, escalated, and measured with metrics.
- Get the plan reviewed and approved, then distribute it to the responders.
- Review and update the plan on a schedule and after each incident.
Framework mapping
- NIST CSF 2.0 — ID.IM-04 — Incident response plans and other cybersecurity plans are established, communicated, maintained, and improved
- CIS Controls v8 — Control 17.4 — Establish and maintain an incident response process
How to move it toward Implemented
- No plan exists yet - the runbook is host-hardening only - so this is the foundational document the host controls (IR-4 handling, IR-6 reporting) need to sit under.
- Author a one-to-two-page incident response (IR) plan for PROD-WEB-01: the handling phases, the Blue/Red/Governance-Risk-Compliance (GRC) roles already named in the README mapped to responsibilities, escalation contacts, and simple metrics (time-to-detect, time-to-contain).
- Get it approved and distributed, and set a review cadence - for example annually and after any incident.
- Attach the approved plan as evidence naming IR-8 to move this Federal Information Processing Standard (FIPS) 199 Moderate asset from 'planned' toward 'Completed'.