Browse 1,193 controls and enhancements across 20 security and privacy families. Use the GovRAMP crosswalk to locate controls referenced by Security Snapshot, Core, and Moderate.
A shared catalog supports common-control planning; designation as a common, hybrid, or system-specific control depends on your organization’s implementation and inheritance decisions.
Sources and crosswalk scope
NIST OSCAL content 5.1.1+u4, retrieved 2026-09-18. GovRAMP Snapshot v1.4 and Core selection from Moderate v1.06 reference the December 2020 Rev. 5 text. Mappings establish exact identifier correspondence, not identical requirements, inherited implementation, or GovRAMP authorization. GovRAMP parameters and additional requirements remain authoritative for each program. Full Moderate, High, and other programs are not mapped here. Withdrawn controls are retained for reference.
Official pinned NIST sourceSHA-256: 81cf2de45ede9aef3de7ce09d65ea9d32f662c483bbf916f6e346292b22f7763
Incident Response · Base control
IR-4 · Incident Handling
Control statement and discussion
NIST control statement
a. Implement an incident handling capability for incidents that is consistent with the incident response plan and includes preparation, detection and analysis, containment, eradication, and recovery;
b. Coordinate incident handling activities with contingency planning activities;
c. Incorporate lessons learned from ongoing incident handling activities into incident response procedures, training, and testing, and implement the resulting changes accordingly; and
d. Ensure the rigor, intensity, scope, and results of incident handling activities are comparable and predictable across the organization.
Discussion
Organizations recognize that incident response capabilities are dependent on the capabilities of organizational systems and the mission and business processes being supported by those systems. Organizations consider incident response as part of the definition, design, and development of mission and business processes and systems. Incident-related information can be obtained from a variety of sources, including audit monitoring, physical access monitoring, and network monitoring; user or administrator reports; and reported supply chain events. An effective incident handling capability includes coordination among many organizational entities (e.g., mission or business owners, system owners, authorizing officials, human resources offices, physical security offices, personnel security offices, legal departments, risk executive [function], operations personnel, procurement offices). Suspected security incidents include the receipt of suspicious email communications that can contain malicious code. Suspected supply chain incidents include the insertion of counterfeit hardware or malicious code into organizational systems or system components. For federal agencies, an incident that involves personally identifiable information is considered a breach. A breach results in unauthorized disclosure, the loss of control, unauthorized acquisition, compromise, or a similar occurrence where a person other than an authorized user accesses or potentially accesses personally identifiable information or an authorized user accesses or potentially accesses such information for other than authorized purposes.
GovRAMP crosswalk
- GovRAMP Security Snapshot Readiness · IR-4 — Direct NIST identifier reference. GovRAMP source matrix
- GovRAMP Core Readiness — 60 Controls · IR-4 — Direct NIST identifier reference. GovRAMP source matrix
- GovRAMP Moderate Readiness · IR-4 — Direct NIST identifier reference. GovRAMP source matrix
Incident Response · Enhancement
IR-4(1) · Automated Incident Handling Processes
View parent controlControl statement and discussion
NIST control statement
Support the incident handling process using [Assignment: automated mechanisms].
Discussion
Automated mechanisms that support incident handling processes include online incident management systems and tools that support the collection of live response data, full network packet capture, and forensic analysis.
GovRAMP crosswalk
- GovRAMP Security Snapshot Readiness · IR-4 (1) — Direct NIST identifier reference. GovRAMP source matrix
- GovRAMP Core Readiness — 60 Controls · IR-4 (1) — Direct NIST identifier reference. GovRAMP source matrix
- GovRAMP Moderate Readiness · IR-4 (1) — Direct NIST identifier reference. GovRAMP source matrix
Incident Response · Enhancement
IR-4(2) · Dynamic Reconfiguration
View parent controlControl statement and discussion
NIST control statement
Include the following types of dynamic reconfiguration for [Assignment: system components] as part of the incident response capability: [Assignment: types of dynamic reconfiguration].
Discussion
Dynamic reconfiguration includes changes to router rules, access control lists, intrusion detection or prevention system parameters, and filter rules for guards or firewalls. Organizations may perform dynamic reconfiguration of systems to stop attacks, misdirect attackers, and isolate components of systems, thus limiting the extent of the damage from breaches or compromises. Organizations include specific time frames for achieving the reconfiguration of systems in the definition of the reconfiguration capability, considering the potential need for rapid response to effectively address cyber threats.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Incident Response · Enhancement
IR-4(3) · Continuity of Operations
View parent controlControl statement and discussion
NIST control statement
Identify [Assignment: classes of incidents] and take the following actions in response to those incidents to ensure continuation of organizational mission and business functions: [Assignment: actions].
Discussion
Classes of incidents include malfunctions due to design or implementation errors and omissions, targeted malicious attacks, and untargeted malicious attacks. Incident response actions include orderly system degradation, system shutdown, fall back to manual mode or activation of alternative technology whereby the system operates differently, employing deceptive measures, alternate information flows, or operating in a mode that is reserved for when systems are under attack. Organizations consider whether continuity of operations requirements during an incident conflict with the capability to automatically disable the system as specified as part of [IR-4(5)](#ir-4.5).
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Incident Response · Enhancement
IR-4(4) · Information Correlation
View parent controlControl statement and discussion
NIST control statement
Correlate incident information and individual incident responses to achieve an organization-wide perspective on incident awareness and response.
Discussion
Sometimes, a threat event, such as a hostile cyber-attack, can only be observed by bringing together information from different sources, including various reports and reporting procedures established by organizations.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Incident Response · Enhancement
IR-4(5) · Automatic Disabling of System
View parent controlControl statement and discussion
NIST control statement
Implement a configurable capability to automatically disable the system if [Assignment: security violations] are detected.
Discussion
Organizations consider whether the capability to automatically disable the system conflicts with continuity of operations requirements specified as part of [CP-2](#cp-2) or [IR-4(3)](#ir-4.3) . Security violations include cyber-attacks that have compromised the integrity of the system or exfiltrated organizational information and serious errors in software programs that could adversely impact organizational missions or functions or jeopardize the safety of individuals.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Incident Response · Enhancement
IR-4(6) · Insider Threats
View parent controlControl statement and discussion
NIST control statement
Implement an incident handling capability for incidents involving insider threats.
Discussion
Explicit focus on handling incidents involving insider threats provides additional emphasis on this type of threat and the need for specific incident handling capabilities to provide appropriate and timely responses.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Incident Response · Enhancement
IR-4(7) · Insider Threats — Intra-organization Coordination
View parent controlControl statement and discussion
NIST control statement
Coordinate an incident handling capability for insider threats that includes the following organizational entities [Assignment: entities].
Discussion
Incident handling for insider threat incidents (e.g., preparation, detection and analysis, containment, eradication, and recovery) requires coordination among many organizational entities, including mission or business owners, system owners, human resources offices, procurement offices, personnel offices, physical security offices, senior agency information security officer, operations personnel, risk executive (function), senior agency official for privacy, and legal counsel. In addition, organizations may require external support from federal, state, and local law enforcement agencies.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Incident Response · Enhancement
IR-4(8) · Correlation with External Organizations
View parent controlControl statement and discussion
NIST control statement
Coordinate with [Assignment: external organizations] to correlate and share [Assignment: incident information] to achieve a cross-organization perspective on incident awareness and more effective incident responses.
Discussion
The coordination of incident information with external organizations—including mission or business partners, military or coalition partners, customers, and developers—can provide significant benefits. Cross-organizational coordination can serve as an important risk management capability. This capability allows organizations to leverage information from a variety of sources to effectively respond to incidents and breaches that could potentially affect the organization’s operations, assets, and individuals.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Incident Response · Enhancement
IR-4(9) · Dynamic Response Capability
View parent controlControl statement and discussion
NIST control statement
Employ [Assignment: dynamic response capabilities] to respond to incidents.
Discussion
The dynamic response capability addresses the timely deployment of new or replacement organizational capabilities in response to incidents. This includes capabilities implemented at the mission and business process level and at the system level.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Incident Response · Enhancement
IR-4(10) · Supply Chain Coordination
View parent controlControl statement and discussion
NIST control statement
Coordinate incident handling activities involving supply chain events with other organizations involved in the supply chain.
Discussion
Organizations involved in supply chain activities include product developers, system integrators, manufacturers, packagers, assemblers, distributors, vendors, and resellers. Supply chain incidents can occur anywhere through or to the supply chain and include compromises or breaches that involve primary or sub-tier providers, information technology products, system components, development processes or personnel, and distribution processes or warehousing facilities. Organizations consider including processes for protecting and sharing incident information in information exchange agreements and their obligations for reporting incidents to government oversight bodies (e.g., Federal Acquisition Security Council).
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Incident Response · Enhancement
IR-4(11) · Integrated Incident Response Team
View parent controlControl statement and discussion
NIST control statement
Establish and maintain an integrated incident response team that can be deployed to any location identified by the organization in [Assignment: time period].
Discussion
An integrated incident response team is a team of experts that assesses, documents, and responds to incidents so that organizational systems and networks can recover quickly and implement the necessary controls to avoid future incidents. Incident response team personnel include forensic and malicious code analysts, tool developers, systems security and privacy engineers, and real-time operations personnel. The incident handling capability includes performing rapid forensic preservation of evidence and analysis of and response to intrusions. For some organizations, the incident response team can be a cross-organizational entity.
An integrated incident response team facilitates information sharing and allows organizational personnel (e.g., developers, implementers, and operators) to leverage team knowledge of the threat and implement defensive measures that enable organizations to deter intrusions more effectively. Moreover, integrated teams promote the rapid detection of intrusions, the development of appropriate mitigations, and the deployment of effective defensive measures. For example, when an intrusion is detected, the integrated team can rapidly develop an appropriate response for operators to implement, correlate the new incident with information on past intrusions, and augment ongoing cyber intelligence development. Integrated incident response teams are better able to identify adversary tactics, techniques, and procedures that are linked to the operations tempo or specific mission and business functions and to define responsive actions in a way that does not disrupt those mission and business functions. Incident response teams can be distributed within organizations to make the capability resilient.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Incident Response · Enhancement
IR-4(12) · Malicious Code and Forensic Analysis
View parent controlControl statement and discussion
NIST control statement
Analyze malicious code and/or other residual artifacts remaining in the system after the incident.
Discussion
When conducted carefully in an isolated environment, analysis of malicious code and other residual artifacts of a security incident or breach can give the organization insight into adversary tactics, techniques, and procedures. It can also indicate the identity or some defining characteristics of the adversary. In addition, malicious code analysis can help the organization develop responses to future incidents.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Incident Response · Enhancement
IR-4(13) · Behavior Analysis
View parent controlControl statement and discussion
NIST control statement
Analyze anomalous or suspected adversarial behavior in or related to [Assignment: environments or resources].
Discussion
If the organization maintains a deception environment, an analysis of behaviors in that environment, including resources targeted by the adversary and timing of the incident or event, can provide insight into adversarial tactics, techniques, and procedures. External to a deception environment, the analysis of anomalous adversarial behavior (e.g., changes in system performance or usage patterns) or suspected behavior (e.g., changes in searches for the location of specific resources) can give the organization such insight.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Incident Response · Enhancement
IR-4(14) · Security Operations Center
View parent controlControl statement and discussion
NIST control statement
Establish and maintain a security operations center.
Discussion
A security operations center (SOC) is the focal point for security operations and computer network defense for an organization. The purpose of the SOC is to defend and monitor an organization’s systems and networks (i.e., cyber infrastructure) on an ongoing basis. The SOC is also responsible for detecting, analyzing, and responding to cybersecurity incidents in a timely manner. The organization staffs the SOC with skilled technical and operational personnel (e.g., security analysts, incident response personnel, systems security engineers) and implements a combination of technical, management, and operational controls (including monitoring, scanning, and forensics tools) to monitor, fuse, correlate, analyze, and respond to threat and security-relevant event data from multiple sources. These sources include perimeter defenses, network devices (e.g., routers, switches), and endpoint agent data feeds. The SOC provides a holistic situational awareness capability to help organizations determine the security posture of the system and organization. A SOC capability can be obtained in a variety of ways. Larger organizations may implement a dedicated SOC while smaller organizations may employ third-party organizations to provide such a capability.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Incident Response · Enhancement
IR-4(15) · Public Relations and Reputation Repair
View parent controlControl statement and discussion
NIST control statement
(a) Manage public relations associated with an incident; and
(b) Employ measures to repair the reputation of the organization.
Discussion
It is important for an organization to have a strategy in place for addressing incidents that have been brought to the attention of the general public, have cast the organization in a negative light, or have affected the organization’s constituents (e.g., partners, customers). Such publicity can be extremely harmful to the organization and affect its ability to carry out its mission and business functions. Taking proactive steps to repair the organization’s reputation is an essential aspect of reestablishing the trust and confidence of its constituents.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Incident Response · Base control
IR-5 · Incident Monitoring
Control statement and discussion
NIST control statement
Track and document incidents.
Discussion
Documenting incidents includes maintaining records about each incident, the status of the incident, and other pertinent information necessary for forensics as well as evaluating incident details, trends, and handling. Incident information can be obtained from a variety of sources, including network monitoring, incident reports, incident response teams, user complaints, supply chain partners, audit monitoring, physical access monitoring, and user and administrator reports. [IR-4](#ir-4) provides information on the types of incidents that are appropriate for monitoring.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · IR-5 — Direct NIST identifier reference. GovRAMP source matrix
Incident Response · Enhancement
IR-5(1) · Automated Tracking, Data Collection, and Analysis
View parent controlControl statement and discussion
NIST control statement
Track incidents and collect and analyze incident information using [Assignment: organization-defined automated mechanisms].
Discussion
Automated mechanisms for tracking incidents and collecting and analyzing incident information include Computer Incident Response Centers or other electronic databases of incidents and network monitoring devices.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Incident Response · Base control
IR-6 · Incident Reporting
Control statement and discussion
NIST control statement
a. Require personnel to report suspected incidents to the organizational incident response capability within [Assignment: time period] ; and
b. Report incident information to [Assignment: authorities].
Discussion
The types of incidents reported, the content and timeliness of the reports, and the designated reporting authorities reflect applicable laws, executive orders, directives, regulations, policies, standards, and guidelines. Incident information can inform risk assessments, control effectiveness assessments, security requirements for acquisitions, and selection criteria for technology products.
GovRAMP crosswalk
- GovRAMP Core Readiness — 60 Controls · IR-6 — Direct NIST identifier reference. GovRAMP source matrix
- GovRAMP Moderate Readiness · IR-6 — Direct NIST identifier reference. GovRAMP source matrix
Incident Response · Enhancement
IR-6(1) · Automated Reporting
View parent controlControl statement and discussion
NIST control statement
Report incidents using [Assignment: automated mechanisms].
Discussion
The recipients of incident reports are specified in [IR-6b](#ir-6_smt.b) . Automated reporting mechanisms include email, posting on websites (with automatic updates), and automated incident response tools and programs.
GovRAMP crosswalk
- GovRAMP Core Readiness — 60 Controls · IR-6 (1) — Direct NIST identifier reference. GovRAMP source matrix
- GovRAMP Moderate Readiness · IR-6 (1) — Direct NIST identifier reference. GovRAMP source matrix
Incident Response · Enhancement
IR-6(2) · Vulnerabilities Related to Incidents
View parent controlControl statement and discussion
NIST control statement
Report system vulnerabilities associated with reported incidents to [Assignment: personnel or roles].
Discussion
Reported incidents that uncover system vulnerabilities are analyzed by organizational personnel including system owners, mission and business owners, senior agency information security officers, senior agency officials for privacy, authorizing officials, and the risk executive (function). The analysis can serve to prioritize and initiate mitigation actions to address the discovered system vulnerability.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Incident Response · Enhancement
IR-6(3) · Supply Chain Coordination
View parent controlControl statement and discussion
NIST control statement
Provide incident information to the provider of the product or service and other organizations involved in the supply chain or supply chain governance for systems or system components related to the incident.
Discussion
Organizations involved in supply chain activities include product developers, system integrators, manufacturers, packagers, assemblers, distributors, vendors, and resellers. Entities that provide supply chain governance include the Federal Acquisition Security Council (FASC). Supply chain incidents include compromises or breaches that involve information technology products, system components, development processes or personnel, distribution processes, or warehousing facilities. Organizations determine the appropriate information to share and consider the value gained from informing external organizations about supply chain incidents, including the ability to improve processes or to identify the root cause of an incident.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · IR-6 (3) — Direct NIST identifier reference. GovRAMP source matrix
Incident Response · Base control
IR-7 · Incident Response Assistance
Control statement and discussion
NIST control statement
Provide an incident response support resource, integral to the organizational incident response capability, that offers advice and assistance to users of the system for the handling and reporting of incidents.
Discussion
Incident response support resources provided by organizations include help desks, assistance groups, automated ticketing systems to open and track incident response tickets, and access to forensics services or consumer redress services, when required.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · IR-7 — Direct NIST identifier reference. GovRAMP source matrix
Incident Response · Enhancement
IR-7(1) · Automation Support for Availability of Information and Support
View parent controlControl statement and discussion
NIST control statement
Increase the availability of incident response information and support using [Assignment: automated mechanisms].
Discussion
Automated mechanisms can provide a push or pull capability for users to obtain incident response assistance. For example, individuals may have access to a website to query the assistance capability, or the assistance capability can proactively send incident response information to users (general distribution or targeted) as part of increasing understanding of current response capabilities and support.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · IR-7 (1) — Direct NIST identifier reference. GovRAMP source matrix
Incident Response · Enhancement
IR-7(2) · Coordination with External Providers
View parent controlControl statement and discussion
NIST control statement
(a) Establish a direct, cooperative relationship between its incident response capability and external providers of system protection capability; and
(b) Identify organizational incident response team members to the external providers.
Discussion
External providers of a system protection capability include the Computer Network Defense program within the U.S. Department of Defense. External providers help to protect, monitor, analyze, detect, and respond to unauthorized activity within organizational information systems and networks. It may be beneficial to have agreements in place with external providers to clarify the roles and responsibilities of each party before an incident occurs.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.