{"data":{"id":"IR-06","name":"Incident Reporting","family":"IR","family_name":"Incident Response","withdrawn":false,"description":"a. Require personnel to report suspected incidents to the organizational incident response capability within [Assignment: organization-defined time period]; and\nb. Report incident information to [Assignment: organization-defined authorities].","supplemental_guidance":"The types of incidents reported, the content and timeliness of the reports, and the designated reporting authorities reflect applicable laws, executive orders, directives, regulations, policies, standards, and guidelines. Incident information can inform risk assessments, control effectiveness assessments, security requirements for acquisitions, and selection criteria for technology products.","enhancements":[{"id":"IR-06(01)","name":"Automated Reporting","statement":"Report incidents using [Assignment: organization-defined automated mechanisms].","baselines":["moderate","high"]},{"id":"IR-06(02)","name":"Vulnerabilities Related to Incidents","statement":"Report system vulnerabilities associated with reported incidents to [Assignment: organization-defined personnel or roles].","baselines":[]},{"id":"IR-06(03)","name":"Supply Chain Coordination","statement":"Provide incident information to the provider of the product or service and other organizations involved in the supply chain or supply chain governance for systems or system components related to the incident.","baselines":["moderate","high"]}],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"nist_800_53":{"rev5":{"id":"IR-06","name":"Incident Reporting","description":"a. Require personnel to report suspected incidents to the organizational incident response capability within [Assignment: organization-defined time period]; and\nb. Report incident information to [Assignment: organization-defined authorities].","discussion":"The types of incidents reported, the content and timeliness of the reports, and the designated reporting authorities reflect applicable laws, executive orders, directives, regulations, policies, standards, and guidelines. Incident information can inform risk assessments, control effectiveness assessments, security requirements for acquisitions, and selection criteria for technology products.","related_controls":["CM-06","CP-02","IR-04","IR-05","IR-08","IR-09"],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"baseline_privacy":true,"new_in_rev5":false,"changes_from_rev4":"Control text eliminates ‘information system security' incidents Discussion significantly revised"}},"compliance_mappings":{"iso_27001_2022":["A.5.5","A.5.25","A.5.26","A.5.27","A.6.8"],"iso_27002_2022":["5.5","5.25","5.26","6.8"],"cobit_2019":["DSS02"],"pci_dss_v4":["10.7","12.10"],"nist_csf_2":["DE.AE-06","DE.AE-08","GV.RM-05","RC.CO-03","RC.CO-04","RS.AN-06","RS.AN-07","RS.CO-02","RS.CO-03","RS.MA-01","RS.MA-02","RS.MA-03","RS.MA-04"],"cis_controls_v8":["CIS 17","CIS 17.2","CIS 17.3","CIS 17.6"],"soc2_tsc":["CC2.3","CC2.3-POF1","CC7.4","CC7.4-POF6","CC7.4-POF13"],"finos_ccc":["CCC-C15"],"iso_42001_2023":["A.3.3","A.8.3","A.8.4"],"iec_62443":[],"asd_e8":[],"nis2":["Art. 21(2)(b)","Art. 23","Art. 29"],"apra_cps_234":["Para 25","Para 26"],"mas_trm":[],"pra_op_resilience":["SS1/21-8.1","SS2/21-15.1"],"bsi_grundschutz":["DER.2.1"],"anssi":["Hygiene.40","SecNumCloud.17.1"],"osfi_b13":["B-13.1.4","B-13.2.5","B-13.3.4"],"finma_circular":["IV.A(44)","IV.A(45)","IV.A(46)","IV.B.a(47)","IV.D(73)","IV.D(74)"],"gdpr":["Art.33(1)","Art.33(2)","Art.34(1)","Art.34(3)"],"dora":["Art.11(7)","Art.14","Art.19(1)","Art.19(4)","Art.20(1)"],"bio2":["5.5","5.25","5.26","6.8"],"rbi_csf":["Annex1.19","ITGRCA.27"],"fisc":["FISC.O4"],"lgpd_bcb":["BCB.Art.5","BCB.Art.8","LGPD.Art.48","LGPD.Art.49"],"hkma_tme1":["TME1.5.4","TME1.7.5"],"mlps_2":["8.1.5.4","8.1.10.10"],"dnb_good_practice":["DNB.15.2"],"cra":["CRA.Art14","CRA.II.4","CRA.II.5"],"swift_cscf":["SWIFT.7.1"],"cbb_tm":["TM-13","TM-16"],"cbuae":["CR-9"],"nca_ecc":["2-13"],"qatar_nia":["IM"],"sama_csf":["2.2","3.6"],"uae_ia":["T11"],"bog_cisd":["CISD-COMP","CISD-VII"],"bom_ctrm":["5.1"],"cbe_csf":["CD-2"],"cbn_csf":["Part3.6"],"popia":["s22","s73-99"],"sa_js2":["JS2-7.4","JS2-9"],"bot_cyber":["Ch4.1"],"cpmi_pfmi":["CG.RR","PFMI.P17"],"eba_ict":["3.5(d)","3.7.5","3.8(d)"],"ecb_croe":["CROE.2.5.1","CROE.2.5.3","CROE.2.7.2"],"ffiec_is":["III.C","III.D"],"hipaa_sr":["§164.308(a)(6)(i)","§164.308(a)(6)(ii)"],"iosco_cyber":["LE-1","RR-1","RR-4","SA-2"],"nydfs_500":["500.16","500.17"],"sebi_cscrf":["RC.CO","RS.CO"],"cmmc_2":["IR"],"nerc_cip":["CIP-008-6"],"nrc_73_54":["RG5.71-B-CP"],"tsa_psd":["SD-1 Sec 2"],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":["RESPONSE"],"api_1164":["Sec 10"],"awia":["AWWA Sec 6"],"iaea_nss":["Sec 7"],"pci_pts":[],"fips_140":[],"cbest":[],"tiber_eu":["TIBER.BT"],"pci_hsm":["10"],"common_criteria":[],"isae_3402":["Clause 10"],"fca_sysc_13":["SYSC 13.4"],"fda_21_cfr_11":["§11.300(c)"],"fda_cyber":["524B-3","CVD-1","CVD-2","INC-1","INC-3"],"hitrust_csf":["11.a","11.b"],"iso_27799":["16.2","16.3"],"lloyds_ms":["CRM.3","MS8.5"],"naic_ds":["4F-a","5","6-a","6-b"],"nhs_dspt":["NDG-6.1","NDG-6.2","NDG-6.3","NDG-6.4"],"pra_ss1_23":["P5.3"],"solvency_ii":["EIOPA-ICT-4.9"],"owasp_masvs_v2":[],"csa_ccm_v4":["BCR-07","CEK-19","DSP-18","SEF-07","SEF-08"],"csa_aicm":["BCR-07","CEK-19","DSP-18","SEF-07","SEF-08","SEF-09"],"ccss_v9":["1.06.2","2.04.2"],"mica":["Art.62(8)"],"basel_sco60":["SCO60.23","SCO60.73","SCO60.82"],"bssc":["GSP-05","GSP-08"],"sec_custody_digital":["SEC-CD-11"],"dpdpa":["Act.8(6)","Rules.7(2)"]},"attack_techniques":[],"metadata":{"last_reviewed":"2026-10-03","review_notes":"2026-10-03: nist_csf_2 RS.AN-06, RS.AN-07, RS.MA-02, RS.MA-03 added from NIST's CSF 2.0 to SP 800-53 Rev 5.2.0 crosswalk (OLIR entry 186), which OSA's mapping now takes as its base.","mapping_status":"complete"},"function":"corrective","used_by_patterns":["SP-001","SP-002","SP-006","SP-007","SP-012","SP-028","SP-029","SP-031","SP-036","SP-039","SP-042","SP-047","SP-048","SP-049","SP-051","SP-054"]}}