Skip to content

IR-4: Incident Handling

An OSCAL Control

Statement

    • a.

      Implement an incident handling capability for incidents that is consistent with the incident response plan and includes preparation, detection and analysis, containment, eradication, and recovery;

    • b.

      Coordinate incident handling activities with contingency planning activities;

    • c.

      Incorporate lessons learned from ongoing incident handling activities into incident response procedures, training, and testing, and implement the resulting changes accordingly; and

    • d.

      Ensure the rigor, intensity, scope, and results of incident handling activities are comparable and predictable across the organization.

      • Requirement:

        The FISMA definition of "incident" shall be used: "An occurrence that actually or imminently jeopardizes, without lawful authority, the confidentiality, integrity, or availability of information or an information system; or constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies."

      • Requirement:

        The service provider ensures that individuals conducting incident handling meet personnel security requirements commensurate with the criticality/sensitivity of the information being processed, stored, and transmitted by the information system.