unified

UC-IR-05 — Assess and validate incident scope, impact, and magnitude

For each declared or suspected incident, estimate the scope of affected systems, data, and business processes and the resulting impact, and validate those estimates as investigation proceeds. Document magnitude assessments — records affected, service disruption, and financial exposure — and update them at defined points so response priority, escalation, and notification decisions rest on current, validated figures.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
Incident Management & Response
type
detective
category
administrative

Details

unified_id
UC-IR-05
title
Assess and validate incident scope, impact, and magnitude
statement
For each declared or suspected incident, estimate the scope of affected systems, data, and business processes and the resulting impact, and validate those estimates as investigation proceeds. Document magnitude assessments — records affected, service disruption, and financial exposure — and update them at defined points so response priority, escalation, and notification decisions rest on current, validated figures.
domain
Incident Management & Response
control_type
detective
control_category
administrative
members
  • framework
    nist-csf-2
    control_id
    DE.AE-04
    coverage
    full
    relationship
    superset_of
  • framework
    nist-csf-2
    control_id
    RS.AN-08
    coverage
    full
    relationship
    superset_of
guidance

    Source

    No record-specific source URL is provided.

    Connections