Incident Response
Incident Response is your plan for when something does go wrong: detecting it, containing it, and reporting it. Assessors want to see a real, tested capability, not a document nobody has ever used.
The 3 Incident Response requirements
14 assessment objectives across this family.
- 3.6.1Incident HandlingEstablish an operational incident-handling capability for organizational systems that includes preparation, detection, analysis, containment, recovery, and user response activities.5 pt✕ POA&M
- 3.6.2Incident ReportingTrack, document, and report incidents to designated officials and/or authorities both internal and external to the organization.5 pt✕ POA&M
- 3.6.3Incident Response TestingTest the organizational incident response capability.1 pt
Build Incident Response, and all 14 families, with an officer
The Level 2 workspace walks all 110 requirements with you at the objective level, generates your SSP, POA&M, and Audit Room from real evidence, gives your assessor a read only seat, and puts a Registered Practitioner alongside you year round.
No credit card, and Level 1 and Level 2 are both open, so sign up for the level your contracts call for. Self assessment and self attestation are law today, DFARS 252.204-7012 is unaffected, and the NIST SP 800-171 Rev 2 baseline is unchanged, so the Level 2 work counts either way.
Questions, answered
How many CMMC Level 2 requirements are in Incident Response?+
The Incident Response family (IR) has 3 of the 110 CMMC Level 2 requirements, assessed against 14 objectives from NIST SP 800-171A.
What is the Incident Response family about?+
Incident Response is your plan for when something does go wrong: detecting it, containing it, and reporting it. Assessors want to see a real, tested capability, not a document nobody has ever used.