Skip to main content
IRO

Incident Response

48 controls

Maintain a tested incident response capability that enables trained responders to identify, analyze, contain, eradicate and recover from incidents according to documented Incident Response Plans (IRPs).

SCF # Control Name Weight NIST CSF Frameworks
IRO-01 Incident Response Policy 10 — Critical Govern 36
IRO-02 Incident Response Operations 9 — Critical Govern 122
IRO-03 Continuous Incident Response Improvements 3 — Low Identify 13
IRO-04 Incident Classification & Prioritization 5 — Medium Respond 36
IRO-05 Indicators of Compromise (IOC) 8 — High Respond 31
IRO-06 Incident Handling 10 — Critical Respond 128
IRO-06.1 Correlation with External Organizations 5 — Medium Respond 12
IRO-07 Automated Incident Handling Processes 1 — Low Respond 19
IRO-07.1 Automated Reporting 9 — Critical Detect 16
IRO-07.2 Automated Tracking, Data Collection & Analysis 1 — Low Detect 10
IRO-07.3 Dynamic Reconfiguration 5 — Medium Respond 9
IRO-07.4 Automatic Disabling of Technology Assets, Applications and/or Services (TAAS) 6 — Medium Respond 5
IRO-08 Incident Response Plan (IRP) 9 — Critical Respond 119
IRO-08.1 Incident Response Plan (IRP) Update 8 — High Respond 56
IRO-09 Incident Response Capabilities Testing 9 — Critical Respond 77
IRO-09.1 Incident Response Capabilities Testing Coordination with Related Plans 7 — High Protect 28
IRO-10 Incident Response Training 9 — Critical Respond 46
IRO-10.1 Simulated Incidents 5 — Medium Respond 11
IRO-10.2 Automated Incident Response Training Environments 5 — Medium Respond 8
IRO-11 Integrated Security Incident Response Team (ISIRT) 9 — Critical Respond 55
IRO-12 Public Relations & Reputation Repair 6 — Medium Recover 9
IRO-13 Chain of Custody & Forensics 9 — Critical Respond 35
IRO-13.1 Licensed Forensic Investigators 9 — Critical Protect 0
IRO-14 Root Cause Analysis (RCA) & Lessons Learned 8 — High Respond 95
IRO-15 Regulatory & Law Enforcement Contacts 9 — Critical Identify 40
IRO-16 Incident Stakeholder Reporting 9 — Critical Respond 138
IRO-16.1 Situational Awareness For Incidents 8 — High Detect 67
IRO-16.2 Cyber Incident Reporting for Sensitive / Regulated Data 9 — Critical Detect 48
IRO-16.3 Serious Incident Reporting 5 — Medium Identify 12
IRO-16.4 Vulnerabilities Related To Incidents 8 — High Respond 10
IRO-17 Incident Tracking Repository 7 — High Identify 5
IRO-17.1 Incident Pattern Analysis 5 — Medium Identify 5
IRO-17.2 Recurring Incident Analysis 5 — Medium Identify 4
IRO-18 Incident Reporting Assistance 5 — Medium Respond 37
IRO-18.1 Automation Support of Availability of Information / Support 1 — Low Respond 14
IRO-19 Supply Chain Coordination 7 — High Respond 32
IRO-19.1 Coordination With External Providers 5 — Medium Respond 20
IRO-20 Sensitive / Regulated Data Spill Response 8 — High Respond 28
IRO-20.1 Sensitive / Regulated Data Spill Responsible Personnel 8 — High Respond 15
IRO-20.2 Sensitive / Regulated Data Spill Training 8 — High Respond 8
IRO-20.3 Post-Sensitive / Regulated Data Spill Operations 8 — High Respond 13
IRO-20.4 Sensitive / Regulated Data Exposure to Unauthorized Personnel 8 — High Respond 10
IRO-21 Detonation Chambers (Sandboxes) 5 — Medium Respond 18
IRO-22 Data Breach 8 — High Respond 26
IRO-23 Artificial Intelligence (AI) & Autonomous Technologies (AAT) Incidents 10 — Critical Respond 2
IRO-24 Cryptographic Incident Response (Emergency Algorithm Transition) 7 — High Protect 1
IRO-25 Embedded Technology Incidents 7 — High Respond 1
IRO-26 Post-Incident Technology Assets, Applications and Services (TAAS) Validation 8 — High Recover 3

The Secure Controls Framework (SCF) is maintained by SCF Council. Use of SCF content is subject to the SCF Terms & Conditions.

Manage SCF Controls in SCF Connect

Streamline your compliance program with automated control tracking, evidence management, and framework mapping.