# IR-06 Incident Reporting

NIST SP 800-53 control. Family: IR Incident Response. Function: corrective. Baselines: low, moderate, high, privacy. Mapping licence: CC BY-SA 4.0.

Statement: a. Require personnel to report suspected incidents to the organizational incident response capability within [Assignment: organization-defined time period]; and b. Report incident information to [Assignment: organization-defined authorities].
Guidance: The types of incidents reported, the content and timeliness of the reports, and the designated reporting authorities reflect applicable laws, executive orders, directives, regulations, policies, standards, and guidelines. Incident information can inform risk assessments, control effectiveness assessments, security requirements for acquisitions, and selection criteria for technology products.

## Enhancements (3)
- IR-06(01) Automated Reporting. Baselines: moderate, high
- IR-06(02) Vulnerabilities Related to Incidents
- IR-06(03) Supply Chain Coordination. Baselines: moderate, high
Each enhancement's statement: /api/v1/controls/IR-06?fields=enhancements

## Patterns that use it (16)
- Critical (1): SP-036 Incident Response
- Important (7): SP-031 Security Monitoring and Response; SP-042 Third Party Risk Management; SP-047 Secure Agentic AI Frameworks; SP-048 Offensive AI and Deepfake Defence (draft); SP-049 AI in Security Operations (draft); SP-051 Tokenised Asset Security Architecture (draft); SP-054 CBDC and Digital Currency Infrastructure (draft)
- Standard (8): SP-001 Client Module; SP-002 Server Module; SP-006 Wireless- Private Network Pattern; SP-007 Wireless- Public Hotspot Pattern; SP-012 Secure Software Development Lifecycle; SP-028 Secure DevOps Pipeline Pattern; SP-029 Zero Trust Architecture; SP-039 Client-Side Encryption and Data Privacy

## Clauses by framework (77 frameworks)
- iso_27001_2022: A.5.5, A.5.25, A.5.26, A.5.27, A.6.8. OSA's own, not in NIST's crosswalk: A.5.25, A.5.26, A.5.27
- iso_27002_2022: 5.5, 5.25, 5.26, 6.8
- cobit_2019: DSS02
- pci_dss_v4: 10.7, 12.10
- nist_csf_2: DE.AE-06, DE.AE-08, GV.RM-05, RC.CO-03, RC.CO-04, RS.AN-06, RS.AN-07, RS.CO-02, RS.CO-03, RS.MA-01, RS.MA-02, RS.MA-03, RS.MA-04. OSA's own, not in NIST's crosswalk: DE.AE-06, DE.AE-08, GV.RM-05, RC.CO-04
- cis_controls_v8: CIS 17, CIS 17.2, CIS 17.3, CIS 17.6
- soc2_tsc: CC2.3, CC2.3-POF1, CC7.4, CC7.4-POF6, CC7.4-POF13
- finos_ccc: CCC-C15
- iso_42001_2023: A.3.3, A.8.3, A.8.4
- nis2: Art. 21(2)(b), Art. 23, Art. 29
- apra_cps_234: Para 25, Para 26
- pra_op_resilience: SS1/21-8.1, SS2/21-15.1
- bsi_grundschutz: DER.2.1
- anssi: Hygiene.40, SecNumCloud.17.1
- osfi_b13: B-13.1.4, B-13.2.5, B-13.3.4
- finma_circular: IV.A(44), IV.A(45), IV.A(46), IV.B.a(47), IV.D(73), IV.D(74)
- gdpr: Art.33(1), Art.33(2), Art.34(1), Art.34(3)
- dora: Art.11(7), Art.14, Art.19(1), Art.19(4), Art.20(1)
- bio2: 5.5, 5.25, 5.26, 6.8
- rbi_csf: Annex1.19, ITGRCA.27
- fisc: FISC.O4
- lgpd_bcb: BCB.Art.5, BCB.Art.8, LGPD.Art.48, LGPD.Art.49
- hkma_tme1: TME1.5.4, TME1.7.5
- mlps_2: 8.1.5.4, 8.1.10.10
- dnb_good_practice: DNB.15.2
- cra: CRA.Art14, CRA.II.4, CRA.II.5
- swift_cscf: SWIFT.7.1
- cbb_tm: TM-13, TM-16
- cbuae: CR-9
- nca_ecc: 2-13
- qatar_nia: IM
- sama_csf: 2.2, 3.6
- uae_ia: T11
- bog_cisd: CISD-COMP, CISD-VII
- bom_ctrm: 5.1
- cbe_csf: CD-2
- cbn_csf: Part3.6
- popia: s22, s73-99
- sa_js2: JS2-7.4, JS2-9
- bot_cyber: Ch4.1
- cpmi_pfmi: CG.RR, PFMI.P17
- eba_ict: 3.5(d), 3.7.5, 3.8(d)
- ecb_croe: CROE.2.5.1, CROE.2.5.3, CROE.2.7.2
- ffiec_is: III.C, III.D
- hipaa_sr: §164.308(a)(6)(i), §164.308(a)(6)(ii)
- iosco_cyber: LE-1, RR-1, RR-4, SA-2
- nydfs_500: 500.16, 500.17
- sebi_cscrf: RC.CO, RS.CO
- cmmc_2: IR
- nerc_cip: CIP-008-6
- nrc_73_54: RG5.71-B-CP
- tsa_psd: SD-1 Sec 2
- doe_c2m2: RESPONSE
- api_1164: Sec 10
- awia: AWWA Sec 6
- iaea_nss: Sec 7
- tiber_eu: TIBER.BT
- pci_hsm: 10
- isae_3402: Clause 10
- fca_sysc_13: SYSC 13.4
- fda_21_cfr_11: §11.300(c)
- fda_cyber: 524B-3, CVD-1, CVD-2, INC-1, INC-3
- hitrust_csf: 11.a, 11.b
- iso_27799: 16.2, 16.3
- lloyds_ms: CRM.3, MS8.5
- naic_ds: 4F-a, 5, 6-a, 6-b
- nhs_dspt: NDG-6.1, NDG-6.2, NDG-6.3, NDG-6.4
- pra_ss1_23: P5.3
- solvency_ii: EIOPA-ICT-4.9
- csa_ccm_v4: BCR-07, CEK-19, DSP-18, SEF-07, SEF-08
- csa_aicm: BCR-07, CEK-19, DSP-18, SEF-07, SEF-08, SEF-09
- ccss_v9: 1.06.2, 2.04.2
- mica: Art.62(8)
- basel_sco60: SCO60.23, SCO60.73, SCO60.82
- bssc: GSP-05, GSP-08
- sec_custody_digital: SEC-CD-11
- dpdpa: Act.8(6), Rules.7(2)
OSA's mapping for iso_27001_2022 and nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/IR-06
- Clauses only: /api/v1/controls/IR-06?fields=mappings
- Page for people: /controls/ir-06/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
