{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Incident Management & Response","type":"detective"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-IR-05","description":"For each declared or suspected incident, estimate the scope of affected systems, data, and business processes and the resulting impact, and validate those estimates as investigation proceeds. Document magnitude assessments — records affected, service disruption, and financial exposure — and update them at defined points so response priority, escalation, and notification decisions rest on current, validated figures.","details":{"control_category":"administrative","control_type":"detective","domain":"Incident Management & Response","guidance":[],"members":[{"control_id":"DE.AE-04","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"},{"control_id":"RS.AN-08","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"}],"statement":"For each declared or suspected incident, estimate the scope of affected systems, data, and business processes and the resulting impact, and validate those estimates as investigation proceeds. Document magnitude assessments — records affected, service disruption, and financial exposure — and update them at defined points so response priority, escalation, and notification decisions rest on current, validated figures.","title":"Assess and validate incident scope, impact, and magnitude","unified_id":"UC-IR-05"},"id":"uc:UC-IR-05","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-IR-05","sourceIds":["nist-csf-2"],"sourceUrl":null,"title":"UC-IR-05 — Assess and validate incident scope, impact, and magnitude","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:02f2f77c825de1afaf629d903735fd0633d1f7e91d742f2a981767d17149332f","properties":{},"sourceDetailPath":"/data/v1/records/wf-g7-9762f11b.json","sourceId":"wf:G7","targetDetailPath":"/data/v1/records/uc-uc-ir-05-0e11ebf5.json","targetId":"uc:UC-IR-05","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:19966fd02f54cce81f20dee195b7fb916d132d716903829889db0ae1e56feef4","properties":{"rationale":"Assessing records affected and magnitude sizes notification obligations, but the operative notification defense is UC-IR-08; assessment is an upstream input that contributes, not the notification act itself.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-ir-05-0e11ebf5.json","sourceId":"uc:UC-IR-05","targetDetailPath":"/data/v1/records/risk-ir-breach-notification-failure-1f01c218.json","targetId":"risk:ir-breach-notification-failure","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:32463a2f8813de9943353d48f9f98997b223cdfe5cc1fbeabc5bb5d236038ed7","properties":{},"sourceDetailPath":"/data/v1/records/wf-c3-4a88b225.json","sourceId":"wf:C3","targetDetailPath":"/data/v1/records/uc-uc-ir-05-0e11ebf5.json","targetId":"uc:UC-IR-05","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5bb59e4c98b691c719678138493071e201727982d39ba0f8b36d1fb55054662c","properties":{"rationale":"Estimating the scope of affected systems (DE.AE-04) reveals the spread and extent of a multi-stage campaign to inform containment.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-ir-05-0e11ebf5.json","sourceId":"uc:UC-IR-05","targetDetailPath":"/data/v1/records/risk-cyber-coordinated-campaign-b5879769.json","targetId":"risk:cyber-coordinated-campaign","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6fde243ca9112e25927ef785ceba2aeda45aeff007051d5c5b30666601337816","properties":{"control_id":"RS.AN-08","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-ir-05-0e11ebf5.json","sourceId":"uc:UC-IR-05","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-rs-an-08-01788005.json","targetId":"ctrl:nist-csf-2:RS.AN-08","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7be65d171a14691c5038495241b15ec5a9c93b5ae7d403edc5cb719b0de75d31","properties":{"rationale":"Validating which data/records were exposed scopes the disclosure so response, remediation, and notification can be targeted.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-ir-05-0e11ebf5.json","sourceId":"uc:UC-IR-05","targetDetailPath":"/data/v1/records/risk-data-breach-unauthorized-disclosure-3b1c296c.json","targetId":"risk:data-breach-unauthorized-disclosure","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:99884d5363a26a6a3590a38c5036ff368ee9f7e526bc2f5c1bed2dde4431d7d5","properties":{"control_id":"DE.AE-04","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-ir-05-0e11ebf5.json","sourceId":"uc:UC-IR-05","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-de-ae-04-186bb6c1.json","targetId":"ctrl:nist-csf-2:DE.AE-04","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c863f809727b948f7005323519f04b234962ef722fdceddcbf1a11381b27821b","properties":{},"sourceDetailPath":"/data/v1/records/wf-r16-5b93e206.json","sourceId":"wf:R16","targetDetailPath":"/data/v1/records/uc-uc-ir-05-0e11ebf5.json","targetId":"uc:UC-IR-05","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d83d297744c90208bca35c4fa450a549a85896fcc320e3709101742f684460d9","properties":{"rationale":"Assessing encryption scope and service disruption sizes ransomware impact so containment and recovery can be prioritized.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-ir-05-0e11ebf5.json","sourceId":"uc:UC-IR-05","targetDetailPath":"/data/v1/records/risk-sdlc-ransomware-32ab67f4.json","targetId":"risk:sdlc-ransomware","type":"mitigates"}],"schemaVersion":1}
