unified
UC-IR-06 — Respond to, contain, and eradicate declared incidents
On declaration of an incident, execute the incident response plan in coordination with internal teams and relevant third parties such as providers, law enforcement, and insurers. Contain the incident using predefined strategies for its category, eradicate the cause by removing malicious artifacts and closing exploited weaknesses, and coordinate handling with contingency and recovery activities through to resolution. Communicate response status as the plan requires and document all response actions taken, feeding lessons into response procedures.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Incident Management & Response
- type
- corrective
- category
- administrative
Details
- unified_id
- UC-IR-06
- title
- Respond to, contain, and eradicate declared incidents
- statement
- On declaration of an incident, execute the incident response plan in coordination with internal teams and relevant third parties such as providers, law enforcement, and insurers. Contain the incident using predefined strategies for its category, eradicate the cause by removing malicious artifacts and closing exploited weaknesses, and coordinate handling with contingency and recovery activities through to resolution. Communicate response status as the plan requires and document all response actions taken, feeding lessons into response procedures.
- domain
- Incident Management & Response
- control_type
- corrective
- control_category
- administrative
- members
- framework
- nist-800-53
- control_id
- IR-4
- coverage
- partial
- delta
- IR-4's preparation and detection/analysis phases satisfied by the IR-planning and continuous-monitoring companion controls; this UC begins at incident declaration
- relationship
- intersects_with
- framework
- nist-csf-2
- control_id
- RS.MA-01
- coverage
- full
- relationship
- superset_of
- framework
- nist-csf-2
- control_id
- RS.MI-01
- coverage
- full
- relationship
- superset_of
- framework
- nist-csf-2
- control_id
- RS.MI-02
- coverage
- full
- relationship
- superset_of
- framework
- iso-27001
- control_id
- A.5.26
- coverage
- full
- relationship
- superset_of
- framework
- soc2
- control_id
- CC7.4
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-IR-06 — Respond to, contain, and eradicate declared incidents maps_to IR-4 — Incident Handling
- framework
- nist-800-53
- control_id
- IR-4
- coverage
- partial
- delta
- IR-4's preparation and detection/analysis phases satisfied by the IR-planning and continuous-monitoring companion controls; this UC begins at incident declaration
- relationship
- intersects_with
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-IR-06 — Respond to, contain, and eradicate declared incidents maps_to RS.MA-01 — Incident Management: The incident response plan is executed in coordination with relevant third parties once an incident is declared
- framework
- nist-csf-2
- control_id
- RS.MA-01
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- SOC 2 Type II Interim Testing tests UC-IR-06 — Respond to, contain, and eradicate declared incidents
- Incident Management Lifecycle operates UC-IR-06 — Respond to, contain, and eradicate declared incidents
- UC-IR-06 — Respond to, contain, and eradicate declared incidents maps_to RS.MI-01 — Incident Mitigation: Incidents are contained
- framework
- nist-csf-2
- control_id
- RS.MI-01
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-IR-06 — Respond to, contain, and eradicate declared incidents mitigates Ransomware disrupting operations and data availability
- strength
- primary
- rationale
- Isolating affected systems halts ransomware encryption spread and eradication removes the malware, directly limiting availability/continuity impact.
- UC-IR-06 — Respond to, contain, and eradicate declared incidents maps_to RS.MI-02 — Incident Mitigation: Incidents are eradicated
- framework
- nist-csf-2
- control_id
- RS.MI-02
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-IR-06 — Respond to, contain, and eradicate declared incidents maps_to A.5.26 — Response to information security incidents
- framework
- iso-27001
- control_id
- A.5.26
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2022
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-IR-06 — Respond to, contain, and eradicate declared incidents mitigates Coordinated multi-stage / APT campaigns
- strength
- primary
- rationale
- Containment stops lateral movement/spread and eradication removes artifacts and closes exploited weaknesses — the direct defense against a persisting multi-stage campaign (RS.MI-01/02).
- UC-IR-06 — Respond to, contain, and eradicate declared incidents mitigates Unauthorized disclosure / breach of sensitive information
- strength
- primary
- rationale
- Containing the incident stops ongoing unauthorized exfiltration and eradication closes the weakness enabling disclosure (RS.MI mitigation).
- Cybersecurity Incident Response operates UC-IR-06 — Respond to, contain, and eradicate declared incidents
- SOC 2 Trust Services Readiness tests UC-IR-06 — Respond to, contain, and eradicate declared incidents
- UC-IR-06 — Respond to, contain, and eradicate declared incidents maps_to CC7.4 — The entity responds to identified security incidents by executing a defined incident response program to understand, contain, remediate, and communicate security incidents, as appropriate.
- framework
- soc2
- control_id
- CC7.4
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2017 TSC
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-IR-06 — Respond to, contain, and eradicate declared incidents