workflow
Cybersecurity Incident Response
Cybersecurity incident-response cycle as a decision-aware workflow spanning detection and validation, scoping, incident declaration and response-plan activation, containment with evidence preservation, eradication and recovery, POA&M updates for the control deficiencies the incident exposed, and a technical lessons-learned retrospective, closed through a disposition decision and archival. The workflow instance runs on the incident record — an Issue item (issue_type=exception, source=management_identified, severity per the org scheme) created at detection, since the schema has no native Incident type — and enriches that one record through to archival rather than creating duplicates. In scope: security events and confirmed incidents affecting the system boundary and its NIST 800-53 IR-family controls — the detection sources (logging/monitoring Control items, UC-LOG-06), affected systems (Process items, UC-ASSET-11), containment and recovery actions, forensic evidence, the deficiency Issues that become the POA&M, and their linked Risk items. Out of scope: the enterprise incident-management ticketing lifecycle and external breach-notification/legal reporting, which run in their own workflows. Where an Incident Management Lifecycle workflow is running, this cycle consumes its handoff package (initial ticket, reporter, affected systems); it hands the closed incident's control-deficiency findings — the open POA&M Issues (issue_type=deficiency) — to the Continuous Controls Monitoring (ISCM) Cycle as shared items it queries directly.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- controls
- department
- it
- lineOfDefense
- operate
Details
- teams
- it
- domains
- controls
- standards
- nist-800-53
- nist-csf-2
- sourceTemplateId
- workflow-library:controls-cybersecurity-incident-response
- releaseId
- sha256:24f03436d3713f92be067a14847e35f7b71d0b34c3bab5fe0e06bcc04156c45f
- canonicalUrl
- https://workflow-library.com/all/?w=controls-cybersecurity-incident-response
- capabilities
- mappingStatus
- mapped
- lineOfDefense
- operate
- controls
- UC-IR-04
- UC-IR-05
- UC-IR-06
- UC-IR-07
- UC-IR-09
- UC-IR-10
- UC-LOG-06
- UC-RISK-14
- UC-ASSET-11
- UC-BCDR-06
- UC-BCDR-07
- UC-BCDR-08
- roleIntegrity
- activityCount
- 0
- ermPhases
- lineRoles
- serviceModes
- warnings
Source
No record-specific source URL is provided.
Download workflow template · Release: sha256:24f03436d3713f92be067a14847e35f7b71d0b34c3bab5fe0e06bcc04156c45f
Connections
- Cybersecurity Incident Response operates UC-RISK-14 — Track deficiencies to closure with remediation action plans
- Cybersecurity Incident Response operates UC-IR-05 — Assess and validate incident scope, impact, and magnitude
- Cybersecurity Incident Response operates UC-IR-07 — Investigate incidents and preserve evidence and records
- Cybersecurity Incident Response operates UC-BCDR-08 — Declare recovery complete and set post-incident norms
- Cybersecurity Incident Response operates UC-LOG-06 — Evaluate events and declare incidents against defined criteria
- Cybersecurity Incident Response operates UC-BCDR-07 — Execute recovery plans to restore systems and operations
- Cybersecurity Incident Response operates UC-ASSET-11 — Improve security plans and processes from operational lessons
- Cybersecurity Incident Response operates UC-BCDR-06 — Resolve operational incidents and eliminate root causes
- Cybersecurity Incident Response operates UC-IR-09 — Recover from incidents using defined initiation criteria
- Cybersecurity Incident Response operates UC-IR-06 — Respond to, contain, and eradicate declared incidents
- Cybersecurity Incident Response operates UC-IR-10 — Learn from incidents and communicate corrective actions
- Cybersecurity Incident Response operates UC-IR-04 — Triage, categorize, and escalate reported security events