Documents how the organization prepares for, detects, contains, eradicates, recovers from, and learns from cybersecurity incidents affecting the system. Covers the controls of the IR family in NIST SP 800-53 r5 and aligns with NIST SP 800-61 r2 (Computer Security Incident Handling Guide).
Public site — unclassified data only.
Do not enter classified, CUI, or other sensitive non-public information into this plan. Use placeholders for sensitive content and complete those fields on an authorized system within the appropriate enclave.