STIGhubSTIGhub
STIGsRMF ControlsCompare
STIGhub— A free STIG search and compliance tool·STIGs updated 3 days ago
Powered by Pylon·Privacy·Terms·© 2026 Beacon Cloud Solutions, Inc.
← All Controls

IR-6

Incident ResponseRev 5organization

Incident Reporting

Baselines:LowModerateHighPrivacy

Control Statement

a. Require personnel to report suspected incidents to the organizational incident response capability within [Assignment: time period] ; and b. Report incident information to [Assignment: authorities].

Supplemental Guidance

The types of incidents reported, the content and timeliness of the reports, and the designated reporting authorities reflect applicable laws, executive orders, directives, regulations, policies, standards, and guidelines. Incident information can inform risk assessments, control effectiveness assessments, security requirements for acquisitions, and selection criteria for technology products.

Related Controls (6)

CM-6CP-2IR-4IR-5IR-8IR-9

CCI Identifiers (4)

CCI-002791Defines authorities to whom incident information is reported.CCI-000834Defines a time period for personnel to report suspected incidents to the organizational incident response capability.CCI-000835Require personnel to report suspected incidents to the organizational incident response capability within the organization-defined time period.CCI-000836Report incident information to organization-defined authorities.

Linked STIG Checks (0)

No STIG checks reference this control.