STIGhub
STIGs
RMF Controls
Compare
← All Controls
IR-1
Incident Response
Rev 5
Policy and Procedures
CCI Identifiers (18)
CCI-000805
Develop and document an organization-level; mission/business process-level; and/or system-level incident response policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance.
CCI-000806
Disseminate an organization-level; mission/business process-level; and/or system-level incident response policy to organization-defined personnel or roles.
CCI-000807
Review and update the current incident response policy in accordance with organization-defined frequency.
CCI-000808
Defines the frequency with which to review and update the current incident response policy.
CCI-000809
Develop and document procedures to facilitate the implementation of incident response policy and associated incident response controls.
CCI-000810
Disseminate the incident response procedures to organization-defined personnel or roles.
CCI-000811
Review and update the current incident response procedures in accordance with organization-defined frequency.
CCI-000812
Defines the frequency with which to review and update the current incident response procedures.
CCI-002776
Defines the personnel or roles to whom the organization-level; mission/business process-level; and/or system-level incident response policy is disseminated.
CCI-002777
Defines the personnel or roles to whom the incident response procedures are disseminated.
CCI-004109
Develop and document an organization-level; mission/business process-level; and/or system-level incident response policy that is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines.
CCI-004110
Designate an organization-defined official to manage the incident response policy.
CCI-004111
Designate an organization-defined official to manage the incident response procedures.
CCI-004112
Defines the official designated to manage the incident response policy and procedures.
CCI-004113
Review and update the current incident response policy following organization-defined events.
CCI-004114
Defines the events for reviewing and updating the current incident response policy.
CCI-004115
Review and update the current incident response procedures following organization-defined events.
CCI-004116
Defines the events for reviewing and updating the current incident response procedures.
Linked STIG Checks (0)
No STIG checks reference this control.