{"data":{"id":"IR-07","name":"Incident Response Assistance","family":"IR","family_name":"Incident Response","withdrawn":false,"description":"Provide an incident response support resource, integral to the organizational incident response capability, that offers advice and assistance to users of the system for the handling and reporting of incidents.","supplemental_guidance":"Incident response support resources provided by organizations include help desks, assistance groups, automated ticketing systems to open and track incident response tickets, and access to forensics services or consumer redress services, when required.","enhancements":[{"id":"IR-07(01)","name":"Automation Support for Availability of Information and Support","statement":"Increase the availability of incident response information and support using [Assignment: organization-defined automated mechanisms].","baselines":["moderate","high"]},{"id":"IR-07(02)","name":"Coordination with External Providers","statement":"a. Establish a direct, cooperative relationship between its incident response capability and external providers of system protection capability; and\nb. Identify organizational incident response team members to the external providers.","baselines":[]}],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"nist_800_53":{"rev5":{"id":"IR-07","name":"Incident Response Assistance","description":"Provide an incident response support resource, integral to the organizational incident response capability, that offers advice and assistance to users of the system for the handling and reporting of incidents.","discussion":"Incident response support resources provided by organizations include help desks, assistance groups, automated ticketing systems to open and track incident response tickets, and access to forensics services or consumer redress services, when required.","related_controls":["AT-02","AT-03","IR-04","IR-06","IR-08","PM-22","PM-26","SA-09","SI-18"],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"baseline_privacy":true,"new_in_rev5":false,"changes_from_rev4":"Control text more general as ‘incidents’ versus ‘security incidents’"}},"compliance_mappings":{"iso_27001_2022":["7.4","A.5.26","A.6.8"],"iso_27002_2022":["5.24","5.26","6.8"],"cobit_2019":["DSS02"],"pci_dss_v4":["12.10"],"nist_csf_2":["GV.RM-05","RC.CO-03","RC.CO-04","RS.CO-02","RS.CO-03","RS.MA-01","RS.MA-04"],"cis_controls_v8":["CIS 17","CIS 17.2","CIS 17.6"],"soc2_tsc":[],"finos_ccc":[],"iso_42001_2023":["A.8.4"],"iec_62443":[],"asd_e8":[],"nis2":["Art. 21(2)(b)","Art. 23"],"apra_cps_234":[],"mas_trm":[],"pra_op_resilience":["SS1/21-8.1"],"bsi_grundschutz":[],"anssi":["Hygiene.40","Hygiene.42","SecNumCloud.17.1"],"osfi_b13":["B-13.2.5","B-13.3.4"],"finma_circular":["IV.A(41)","IV.C(70)","IV.D(71)"],"gdpr":["Art.33(1)","Art.34(1)","Art.34(2)"],"dora":["Art.11(7)","Art.14","Art.17(3)(d)","Art.22(1)"],"bio2":["5.24","5.26","6.8"],"rbi_csf":["Annex1.19","ITGRCA.27"],"fisc":["FISC.O4"],"lgpd_bcb":["BCB.Art.5","BCB.Art.7","LGPD.Art.48"],"hkma_tme1":["TME1.5.4","TME1.7.5"],"mlps_2":[],"dnb_good_practice":[],"cra":["CRA.II.6"],"swift_cscf":[],"cbb_tm":["TM-13"],"cbuae":["CR-9"],"nca_ecc":["2-13"],"qatar_nia":["IM"],"sama_csf":["3.6"],"uae_ia":["T11"],"bog_cisd":["CISD-VII"],"bom_ctrm":["5.1"],"cbe_csf":["CD-2"],"cbn_csf":["Part3.6"],"popia":["s22"],"sa_js2":["JS2-7.4"],"bot_cyber":["Ch4.1"],"cpmi_pfmi":["CG.RR"],"eba_ict":["3.5(d)","3.7.5","3.8(d)"],"ecb_croe":["CROE.2.5.1","CROE.2.5.3"],"ffiec_is":["III.D"],"hipaa_sr":["§164.308(a)(6)(i)","§164.308(a)(6)(ii)"],"iosco_cyber":["RR-1","RR-4"],"nydfs_500":["500.16"],"sebi_cscrf":["RS.MA"],"cmmc_2":["IR"],"nerc_cip":[],"nrc_73_54":[],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":[],"api_1164":[],"awia":[],"iaea_nss":[],"pci_pts":[],"fips_140":[],"cbest":[],"tiber_eu":["TIBER.BT"],"pci_hsm":[],"common_criteria":[],"isae_3402":["Clause 10"],"fca_sysc_13":[],"fda_21_cfr_11":[],"fda_cyber":["524B-3","CVD-1","INC-1"],"hitrust_csf":["11.a"],"iso_27799":["16.1"],"lloyds_ms":["MS8.5"],"naic_ds":["4F-a"],"nhs_dspt":["NDG-6.1"],"pra_ss1_23":[],"solvency_ii":["EIOPA-ICT-4.9"],"owasp_masvs_v2":[],"csa_ccm_v4":["SEF-07"],"csa_aicm":["SEF-07"],"ccss_v9":[],"mica":["Art.62(8)","Art.64(1)"],"basel_sco60":["SCO60.73"],"bssc":[],"sec_custody_digital":["SEC-CD-11"],"dpdpa":[]},"attack_techniques":[],"metadata":{"last_reviewed":"2026-10-03","review_notes":"2026-10-03: nist_csf_2 RS.CO-03 added from NIST's CSF 2.0 to SP 800-53 Rev 5.2.0 crosswalk (OLIR entry 186), which OSA's mapping now takes as its base.","mapping_status":"complete"},"function":"corrective","used_by_patterns":["SP-001","SP-002","SP-006","SP-007","SP-019","SP-021","SP-023","SP-031","SP-036"]}}