IR-06 Incident Reporting
Incident Response
Description
a. Require personnel to report suspected incidents to the organizational incident response capability within [Assignment: organization-defined time period]; and b. Report incident information to [Assignment: organization-defined authorities].
Supplemental Guidance
The types of incidents reported, the content and timeliness of the reports, and the designated reporting authorities reflect applicable laws, executive orders, directives, regulations, policies, standards, and guidelines. Incident information can inform risk assessments, control effectiveness assessments, security requirements for acquisitions, and selection criteria for technology products.
Changes from Rev 4
Control text eliminates ‘information system security' incidents Discussion significantly revised
Enhancements (3)
What NIST adds to this control. Select one to read its statement.
IR-06(01) Automated Reporting ModerateHigh
Report incidents using [Assignment: organization-defined automated mechanisms].
IR-06(02) Vulnerabilities Related to Incidents
Report system vulnerabilities associated with reported incidents to [Assignment: organization-defined personnel or roles].
IR-06(03) Supply Chain Coordination ModerateHigh
Provide incident information to the provider of the product or service and other organizations involved in the supply chain or supply chain governance for systems or system components related to the incident.
Patterns that use this control (16)
Grouped by the emphasis each pattern gives it.
Critical (1)
Important (7)
- SP-031 Security Monitoring and Response
- SP-042 Third Party Risk Management
- SP-047 Secure Agentic AI Frameworks
- SP-048 Offensive AI and Deepfake Defence (draft)
- SP-049 AI in Security Operations (draft)
- SP-051 Tokenised Asset Security Architecture (draft)
- SP-054 CBDC and Digital Currency Infrastructure (draft)