workflow

Cybersecurity Incident Response

Cybersecurity incident-response cycle as a decision-aware workflow spanning detection and validation, scoping, incident declaration and response-plan activation, containment with evidence preservation, eradication and recovery, POA&M updates for the control deficiencies the incident exposed, and a technical lessons-learned retrospective, closed through a disposition decision and archival. The workflow instance runs on the incident record — an Issue item (issue_type=exception, source=management_identified, severity per the org scheme) created at detection, since the schema has no native Incident type — and enriches that one record through to archival rather than creating duplicates. In scope: security events and confirmed incidents affecting the system boundary and its NIST 800-53 IR-family controls — the detection sources (logging/monitoring Control items, UC-LOG-06), affected systems (Process items, UC-ASSET-11), containment and recovery actions, forensic evidence, the deficiency Issues that become the POA&M, and their linked Risk items. Out of scope: the enterprise incident-management ticketing lifecycle and external breach-notification/legal reporting, which run in their own workflows. Where an Incident Management Lifecycle workflow is running, this cycle consumes its handoff package (initial ticket, reporter, affected systems); it hands the closed incident's control-deficiency findings — the open POA&M Issues (issue_type=deficiency) — to the Continuous Controls Monitoring (ISCM) Cycle as shared items it queries directly.

Record JSON · Open in map · Data retrieval guide

Catalog revision: f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e. A connection does not establish full coverage.

Attributes

domain
controls
department
it
lineOfDefense
operate

Details

teams
  • it
domains
  • controls
standards
  • nist-800-53
  • nist-csf-2
sourceTemplateId
workflow-library:controls-cybersecurity-incident-response
releaseId
sha256:b342ec779aa548d21cfb8010cb2c2d7fc8e2d3bd4c0753cbb4fb405dd4e1e2cf
canonicalUrl
https://assureswarm.com/workflows/all/?w=controls-cybersecurity-incident-response
capabilities
    mappingStatus
    mapped
    lineOfDefense
    operate
    controls
    • UC-IR-04
    • UC-IR-05
    • UC-IR-06
    • UC-IR-07
    • UC-IR-09
    • UC-IR-10
    • UC-LOG-06
    • UC-RISK-14
    • UC-ASSET-11
    • UC-BCDR-06
    • UC-BCDR-07
    • UC-BCDR-08
    roleIntegrity
    activityCount
    0
    ermPhases
      lineRoles
        serviceModes
          warnings

            Source

            No record-specific source URL is provided.

            Download workflow template · Release: sha256:b342ec779aa548d21cfb8010cb2c2d7fc8e2d3bd4c0753cbb4fb405dd4e1e2cf

            Connections