unified
UC-IR-01 — Maintain an approved incident response plan
Maintain a written incident response plan that defines the mission and scope of the response capability, incident definitions and severity structure, roles, responsibilities, and communication paths, and how the capability coordinates with business continuity and third parties. Have the plan approved by designated management, distribute it to named response personnel, and review and update it on a defined frequency and after significant incidents or organizational changes, protecting it from unauthorized disclosure and modification.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Incident Management & Response
- type
- corrective
- category
- administrative
Details
- unified_id
- UC-IR-01
- title
- Maintain an approved incident response plan
- statement
- Maintain a written incident response plan that defines the mission and scope of the response capability, incident definitions and severity structure, roles, responsibilities, and communication paths, and how the capability coordinates with business continuity and third parties. Have the plan approved by designated management, distribute it to named response personnel, and review and update it on a defined frequency and after significant incidents or organizational changes, protecting it from unauthorized disclosure and modification.
- domain
- Incident Management & Response
- control_type
- corrective
- control_category
- administrative
- members
- framework
- nist-800-53
- control_id
- IR-8
- coverage
- full
- relationship
- superset_of
- framework
- iso-27001
- control_id
- A.5.24
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-IR-01 — Maintain an approved incident response plan mitigates Failure to detect, assess, and notify breaches on time
- strength
- related
- rationale
- Plan defines communication paths and third-party/BC coordination that the downstream breach-notification chain depends on.
- UC-IR-01 — Maintain an approved incident response plan mitigates No or insufficient incident-response procedures
- strength
- primary
- rationale
- The approved, distributed, periodically-reviewed IR plan is the documented response procedure whose absence defines the risk.
- Cybersecurity Assurance Review tests UC-IR-01 — Maintain an approved incident response plan
- UC-IR-01 — Maintain an approved incident response plan maps_to A.5.24 — Information security incident management planning and preparation
- framework
- iso-27001
- control_id
- A.5.24
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2022
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-IR-01 — Maintain an approved incident response plan
- Incident Response Readiness Program operates UC-IR-01 — Maintain an approved incident response plan
- UC-IR-01 — Maintain an approved incident response plan maps_to IR-8 — Incident Response Plan
- framework
- nist-800-53
- control_id
- IR-8
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.