{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Incident Management & Response","type":"corrective"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-IR-06","description":"On declaration of an incident, execute the incident response plan in coordination with internal teams and relevant third parties such as providers, law enforcement, and insurers. Contain the incident using predefined strategies for its category, eradicate the cause by removing malicious artifacts and closing exploited weaknesses, and coordinate handling with contingency and recovery activities through to resolution. Communicate response status as the plan requires and document all response actions taken, feeding lessons into response procedures.","details":{"control_category":"administrative","control_type":"corrective","domain":"Incident Management & Response","guidance":[],"members":[{"control_id":"IR-4","coverage":"partial","delta":"IR-4's preparation and detection/analysis phases satisfied by the IR-planning and continuous-monitoring companion controls; this UC begins at incident declaration","framework":"nist-800-53","relationship":"intersects_with"},{"control_id":"RS.MA-01","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"},{"control_id":"RS.MI-01","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"},{"control_id":"RS.MI-02","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"},{"control_id":"A.5.26","coverage":"full","framework":"iso-27001","relationship":"superset_of"},{"control_id":"CC7.4","coverage":"full","framework":"soc2","relationship":"superset_of"}],"statement":"On declaration of an incident, execute the incident response plan in coordination with internal teams and relevant third parties such as providers, law enforcement, and insurers. Contain the incident using predefined strategies for its category, eradicate the cause by removing malicious artifacts and closing exploited weaknesses, and coordinate handling with contingency and recovery activities through to resolution. Communicate response status as the plan requires and document all response actions taken, feeding lessons into response procedures.","title":"Respond to, contain, and eradicate declared incidents","unified_id":"UC-IR-06"},"id":"uc:UC-IR-06","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-IR-06","sourceIds":["iso-27001","nist-800-53","nist-csf-2","soc2"],"sourceUrl":null,"title":"UC-IR-06 — Respond to, contain, and eradicate declared incidents","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:11898ead1c00ce5746570821821b2a61b67626ad8d699ad6b1e6f616f6468e88","properties":{"control_id":"IR-4","coverage":"partial","delta":"IR-4's preparation and detection/analysis phases satisfied by the IR-planning and continuous-monitoring companion controls; this UC begins at incident declaration","framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-ir-06-0b166c2a.json","sourceId":"uc:UC-IR-06","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ir-4-a97f1795.json","targetId":"ctrl:nist-800-53:IR-4","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1df8d9a31746e7e0735819867e71233b5154034bf7bde1810ca86e04379a472a","properties":{"control_id":"RS.MA-01","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-ir-06-0b166c2a.json","sourceId":"uc:UC-IR-06","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-rs-ma-01-345520d7.json","targetId":"ctrl:nist-csf-2:RS.MA-01","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:25d644bb7b8df30ae1054fba715a6a57c369998686697bc3284c97524d266cab","properties":{},"sourceDetailPath":"/data/v1/records/wf-d24-a9f3daf6.json","sourceId":"wf:D24","targetDetailPath":"/data/v1/records/uc-uc-ir-06-0b166c2a.json","targetId":"uc:UC-IR-06","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:32117b74316c0ed4fca30e389d844f825f65fc9cb76edf2c7568f26c308ccf2b","properties":{},"sourceDetailPath":"/data/v1/records/wf-g7-9762f11b.json","sourceId":"wf:G7","targetDetailPath":"/data/v1/records/uc-uc-ir-06-0b166c2a.json","targetId":"uc:UC-IR-06","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:397402a14fc3ab8147e3dad04fd0c24c6a56607e808018f1e023170a01f738bf","properties":{"control_id":"RS.MI-01","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-ir-06-0b166c2a.json","sourceId":"uc:UC-IR-06","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-rs-mi-01-327ee285.json","targetId":"ctrl:nist-csf-2:RS.MI-01","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:429055b510c5d2ecd7e7e6e78338ed050d10ad73d27812fb5fe186d51da02645","properties":{"rationale":"Isolating affected systems halts ransomware encryption spread and eradication removes the malware, directly limiting availability/continuity impact.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-ir-06-0b166c2a.json","sourceId":"uc:UC-IR-06","targetDetailPath":"/data/v1/records/risk-sdlc-ransomware-32ab67f4.json","targetId":"risk:sdlc-ransomware","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5ac7c1e1423573b4a3377bedfba2cf15a41b7666fe4da3ee6e6f51adf087f8be","properties":{"control_id":"RS.MI-02","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-ir-06-0b166c2a.json","sourceId":"uc:UC-IR-06","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-rs-mi-02-c994309c.json","targetId":"ctrl:nist-csf-2:RS.MI-02","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:60f2083b85eec41e5629c01567e3bc03ebc043b72a575f38df3d7bd42caa9029","properties":{"control_id":"A.5.26","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-ir-06-0b166c2a.json","sourceId":"uc:UC-IR-06","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-26-863e832e.json","targetId":"ctrl:iso-27001:A.5.26","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7224cf4c9eebce6b4b910f2a958b9083a933dd59078e90805ca1b81c2747aadc","properties":{"rationale":"Containment stops lateral movement/spread and eradication removes artifacts and closes exploited weaknesses — the direct defense against a persisting multi-stage campaign (RS.MI-01/02).","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-ir-06-0b166c2a.json","sourceId":"uc:UC-IR-06","targetDetailPath":"/data/v1/records/risk-cyber-coordinated-campaign-b5879769.json","targetId":"risk:cyber-coordinated-campaign","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c30f912201dd177435429da28a4c4815dfd71e9d8b2514a6f647927c4f69df1e","properties":{"rationale":"Containing the incident stops ongoing unauthorized exfiltration and eradication closes the weakness enabling disclosure (RS.MI mitigation).","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-ir-06-0b166c2a.json","sourceId":"uc:UC-IR-06","targetDetailPath":"/data/v1/records/risk-data-breach-unauthorized-disclosure-3b1c296c.json","targetId":"risk:data-breach-unauthorized-disclosure","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:cc7c3ee700e38ba8fafcfd0fee70b0bcb9c6547e0b2871c327c4baf7358cf7bd","properties":{},"sourceDetailPath":"/data/v1/records/wf-c3-4a88b225.json","sourceId":"wf:C3","targetDetailPath":"/data/v1/records/uc-uc-ir-06-0b166c2a.json","targetId":"uc:UC-IR-06","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d231540a867ba75a013615c3fa4f19d37d293c16fc12f2966d10c0e08bf1433c","properties":{},"sourceDetailPath":"/data/v1/records/wf-a15-e859f6b8.json","sourceId":"wf:A15","targetDetailPath":"/data/v1/records/uc-uc-ir-06-0b166c2a.json","targetId":"uc:UC-IR-06","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:eee175d1643d80beca9bb14d6c6a26c300e0257e140779f9e67825e4b2568c77","properties":{"control_id":"CC7.4","coverage":"full","delta":null,"framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-ir-06-0b166c2a.json","sourceId":"uc:UC-IR-06","targetDetailPath":"/data/v1/records/ctrl-soc2-cc7-4-4e5ce771.json","targetId":"ctrl:soc2:CC7.4","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f064c414afb52d61f93432c3c241af4ccdaa0ac946ad40b12e98a64f80344e07","properties":{},"sourceDetailPath":"/data/v1/records/wf-d06-c9616fb8.json","sourceId":"wf:D06","targetDetailPath":"/data/v1/records/uc-uc-ir-06-0b166c2a.json","targetId":"uc:UC-IR-06","type":"tests"}],"schemaVersion":1}
