unified
UC-IR-05 — Assess and validate incident scope, impact, and magnitude
For each declared or suspected incident, estimate the scope of affected systems, data, and business processes and the resulting impact, and validate those estimates as investigation proceeds. Document magnitude assessments — records affected, service disruption, and financial exposure — and update them at defined points so response priority, escalation, and notification decisions rest on current, validated figures.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Incident Management & Response
- type
- detective
- category
- administrative
Details
- unified_id
- UC-IR-05
- title
- Assess and validate incident scope, impact, and magnitude
- statement
- For each declared or suspected incident, estimate the scope of affected systems, data, and business processes and the resulting impact, and validate those estimates as investigation proceeds. Document magnitude assessments — records affected, service disruption, and financial exposure — and update them at defined points so response priority, escalation, and notification decisions rest on current, validated figures.
- domain
- Incident Management & Response
- control_type
- detective
- control_category
- administrative
- members
- framework
- nist-csf-2
- control_id
- DE.AE-04
- coverage
- full
- relationship
- superset_of
- framework
- nist-csf-2
- control_id
- RS.AN-08
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- Incident Management Lifecycle operates UC-IR-05 — Assess and validate incident scope, impact, and magnitude
- UC-IR-05 — Assess and validate incident scope, impact, and magnitude mitigates Failure to detect, assess, and notify breaches on time
- strength
- related
- rationale
- Assessing records affected and magnitude sizes notification obligations, but the operative notification defense is UC-IR-08; assessment is an upstream input that contributes, not the notification act itself.
- Cybersecurity Incident Response operates UC-IR-05 — Assess and validate incident scope, impact, and magnitude
- UC-IR-05 — Assess and validate incident scope, impact, and magnitude mitigates Coordinated multi-stage / APT campaigns
- strength
- related
- rationale
- Estimating the scope of affected systems (DE.AE-04) reveals the spread and extent of a multi-stage campaign to inform containment.
- UC-IR-05 — Assess and validate incident scope, impact, and magnitude maps_to RS.AN-08 — Incident Analysis: An incident's magnitude is estimated and validated
- framework
- nist-csf-2
- control_id
- RS.AN-08
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-IR-05 — Assess and validate incident scope, impact, and magnitude mitigates Unauthorized disclosure / breach of sensitive information
- strength
- related
- rationale
- Validating which data/records were exposed scopes the disclosure so response, remediation, and notification can be targeted.
- UC-IR-05 — Assess and validate incident scope, impact, and magnitude maps_to DE.AE-04 — Adverse Event Analysis: The estimated impact and scope of adverse events are understood
- framework
- nist-csf-2
- control_id
- DE.AE-04
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Privacy Breach Assessment & Notification operates UC-IR-05 — Assess and validate incident scope, impact, and magnitude
- UC-IR-05 — Assess and validate incident scope, impact, and magnitude mitigates Ransomware disrupting operations and data availability
- strength
- related
- rationale
- Assessing encryption scope and service disruption sizes ransomware impact so containment and recovery can be prioritized.