unified

UC-IR-06 — Respond to, contain, and eradicate declared incidents

On declaration of an incident, execute the incident response plan in coordination with internal teams and relevant third parties such as providers, law enforcement, and insurers. Contain the incident using predefined strategies for its category, eradicate the cause by removing malicious artifacts and closing exploited weaknesses, and coordinate handling with contingency and recovery activities through to resolution. Communicate response status as the plan requires and document all response actions taken, feeding lessons into response procedures.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
Incident Management & Response
type
corrective
category
administrative

Details

unified_id
UC-IR-06
title
Respond to, contain, and eradicate declared incidents
statement
On declaration of an incident, execute the incident response plan in coordination with internal teams and relevant third parties such as providers, law enforcement, and insurers. Contain the incident using predefined strategies for its category, eradicate the cause by removing malicious artifacts and closing exploited weaknesses, and coordinate handling with contingency and recovery activities through to resolution. Communicate response status as the plan requires and document all response actions taken, feeding lessons into response procedures.
domain
Incident Management & Response
control_type
corrective
control_category
administrative
members
  • framework
    nist-800-53
    control_id
    IR-4
    coverage
    partial
    delta
    IR-4's preparation and detection/analysis phases satisfied by the IR-planning and continuous-monitoring companion controls; this UC begins at incident declaration
    relationship
    intersects_with
  • framework
    nist-csf-2
    control_id
    RS.MA-01
    coverage
    full
    relationship
    superset_of
  • framework
    nist-csf-2
    control_id
    RS.MI-01
    coverage
    full
    relationship
    superset_of
  • framework
    nist-csf-2
    control_id
    RS.MI-02
    coverage
    full
    relationship
    superset_of
  • framework
    iso-27001
    control_id
    A.5.26
    coverage
    full
    relationship
    superset_of
  • framework
    soc2
    control_id
    CC7.4
    coverage
    full
    relationship
    superset_of
guidance

    Source

    No record-specific source URL is provided.

    Connections