workflow

Cybersecurity Incident Response

Cybersecurity incident-response cycle as a decision-aware workflow spanning detection and validation, scoping, incident declaration and response-plan activation, containment with evidence preservation, eradication and recovery, POA&M updates for the control deficiencies the incident exposed, and a technical lessons-learned retrospective, closed through a disposition decision and archival. The workflow instance runs on the incident record — an Issue item (issue_type=exception, source=management_identified, severity per the org scheme) created at detection, since the schema has no native Incident type — and enriches that one record through to archival rather than creating duplicates. In scope: security events and confirmed incidents affecting the system boundary and its NIST 800-53 IR-family controls — the detection sources (logging/monitoring Control items, UC-LOG-06), affected systems (Process items, UC-ASSET-11), containment and recovery actions, forensic evidence, the deficiency Issues that become the POA&M, and their linked Risk items. Out of scope: the enterprise incident-management ticketing lifecycle and external breach-notification/legal reporting, which run in their own workflows. Where an Incident Management Lifecycle workflow is running, this cycle consumes its handoff package (initial ticket, reporter, affected systems); it hands the closed incident's control-deficiency findings — the open POA&M Issues (issue_type=deficiency) — to the Continuous Controls Monitoring (ISCM) Cycle as shared items it queries directly.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
controls
department
it
lineOfDefense
operate

Details

teams
  • it
domains
  • controls
standards
  • nist-800-53
  • nist-csf-2
sourceTemplateId
workflow-library:controls-cybersecurity-incident-response
releaseId
sha256:24f03436d3713f92be067a14847e35f7b71d0b34c3bab5fe0e06bcc04156c45f
canonicalUrl
https://workflow-library.com/all/?w=controls-cybersecurity-incident-response
capabilities
    mappingStatus
    mapped
    lineOfDefense
    operate
    controls
    • UC-IR-04
    • UC-IR-05
    • UC-IR-06
    • UC-IR-07
    • UC-IR-09
    • UC-IR-10
    • UC-LOG-06
    • UC-RISK-14
    • UC-ASSET-11
    • UC-BCDR-06
    • UC-BCDR-07
    • UC-BCDR-08
    roleIntegrity
    activityCount
    0
    ermPhases
      lineRoles
        serviceModes
          warnings

            Source

            No record-specific source URL is provided.

            Download workflow template · Release: sha256:24f03436d3713f92be067a14847e35f7b71d0b34c3bab5fe0e06bcc04156c45f

            Connections