{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Incident Management & Response","type":"corrective"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-IR-01","description":"Maintain a written incident response plan that defines the mission and scope of the response capability, incident definitions and severity structure, roles, responsibilities, and communication paths, and how the capability coordinates with business continuity and third parties. Have the plan approved by designated management, distribute it to named response personnel, and review and update it on a defined frequency and after significant incidents or organizational changes, protecting it from unauthorized disclosure and modification.","details":{"control_category":"administrative","control_type":"corrective","domain":"Incident Management & Response","guidance":[],"members":[{"control_id":"IR-8","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"A.5.24","coverage":"full","framework":"iso-27001","relationship":"superset_of"}],"statement":"Maintain a written incident response plan that defines the mission and scope of the response capability, incident definitions and severity structure, roles, responsibilities, and communication paths, and how the capability coordinates with business continuity and third parties. Have the plan approved by designated management, distribute it to named response personnel, and review and update it on a defined frequency and after significant incidents or organizational changes, protecting it from unauthorized disclosure and modification.","title":"Maintain an approved incident response plan","unified_id":"UC-IR-01"},"id":"uc:UC-IR-01","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-IR-01","sourceIds":["iso-27001","nist-800-53"],"sourceUrl":null,"title":"UC-IR-01 — Maintain an approved incident response plan","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1b38252b326129e0fbbe6888bb11bf3889a21a32ec21fc24a2336469973d6cb7","properties":{"rationale":"Plan defines communication paths and third-party/BC coordination that the downstream breach-notification chain depends on.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-ir-01-e7711d29.json","sourceId":"uc:UC-IR-01","targetDetailPath":"/data/v1/records/risk-ir-breach-notification-failure-1f01c218.json","targetId":"risk:ir-breach-notification-failure","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:21f52a7b63a090bb9662aafb971b1de101c6939fba6c050130650bb4c165076f","properties":{"rationale":"The approved, distributed, periodically-reviewed IR plan is the documented response procedure whose absence defines the risk.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-ir-01-e7711d29.json","sourceId":"uc:UC-IR-01","targetDetailPath":"/data/v1/records/risk-ir-no-response-procedures-90eb7ba1.json","targetId":"risk:ir-no-response-procedures","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2dcfa618d47adf7e586b6a2709784b266b1cfe1396ca8f761a7868b51db3f768","properties":{},"sourceDetailPath":"/data/v1/records/wf-a1-f09c8201.json","sourceId":"wf:A1","targetDetailPath":"/data/v1/records/uc-uc-ir-01-e7711d29.json","targetId":"uc:UC-IR-01","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:60288c7b615dd45071fe47c6f5941bd0186a54666ec26aa84d96505dc1e37e13","properties":{"control_id":"A.5.24","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-ir-01-e7711d29.json","sourceId":"uc:UC-IR-01","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-24-904c429f.json","targetId":"ctrl:iso-27001:A.5.24","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7a11c717656080a2637bbde85717ec924fba9d44274b72fcc0bead1a26ac80e1","properties":{},"sourceDetailPath":"/data/v1/records/wf-d06-c9616fb8.json","sourceId":"wf:D06","targetDetailPath":"/data/v1/records/uc-uc-ir-01-e7711d29.json","targetId":"uc:UC-IR-01","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9cf2658fbf30d3fb1affa64301fe9cb19514879ebc6204bdb55c4c7280dfeb06","properties":{},"sourceDetailPath":"/data/v1/records/wf-c57-d3460b57.json","sourceId":"wf:C57","targetDetailPath":"/data/v1/records/uc-uc-ir-01-e7711d29.json","targetId":"uc:UC-IR-01","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e539ba86ac8d7b6668ff499fd11bf83dab0bdd2c361476cffea1fe56c2918716","properties":{"control_id":"IR-8","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-ir-01-e7711d29.json","sourceId":"uc:UC-IR-01","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ir-8-4435b712.json","targetId":"ctrl:nist-800-53:IR-8","type":"maps_to"}],"schemaVersion":1}
