# IR-03 Incident Response Testing

NIST SP 800-53 control. Family: IR Incident Response. Function: corrective. Baselines: moderate, high, privacy. Mapping licence: CC BY-SA 4.0.

Statement: Test the effectiveness of the incident response capability for the system [Assignment: organization-defined frequency] using the following tests: [Assignment: organization-defined tests].
Guidance: Organizations test incident response capabilities to determine their effectiveness and identify potential weaknesses or deficiencies. Incident response testing includes the use of checklists, walk-through or tabletop exercises, and simulations (parallel or full interrupt). Incident response testing can include a determination of the effects on organizational operations and assets and individuals due to incident response. The use of qualitative and quantitative data aids in determining the effectiveness of incident response processes.

## Enhancements (3)
- IR-03(01) Automated Testing
- IR-03(02) Coordination with Related Plans. Baselines: moderate, high
- IR-03(03) Continuous Improvement
Each enhancement's statement: /api/v1/controls/IR-03?fields=enhancements

## Patterns that use it (6)
- Critical (3): SP-034 Cyber Resilience; SP-035 Offensive Security Testing; SP-036 Incident Response
- Important (1): SP-025 Advanced Monitoring and Detection
- Standard (2): SP-001 Client Module; SP-002 Server Module

## Clauses by framework (55 frameworks)
- iso_27001_2022: A.5.24, A.5.27. OSA's own, not in NIST's crosswalk: A.5.24, A.5.27
- iso_27002_2022: 5.24, 5.27
- cobit_2019: DSS02
- pci_dss_v4: 12.10
- nist_csf_2: ID.IM-02, ID.IM-04, RC.RP-06. OSA's own, not in NIST's crosswalk: ID.IM-04, RC.RP-06
- cis_controls_v8: CIS 16.3, CIS 17, CIS 17.7, CIS 17.8
- iso_42001_2023: A.8.4
- nis2: Art. 21(2)(b)
- pra_op_resilience: SS1/21-6.1, SS1/21-6.2
- anssi: Hygiene.35, SecNumCloud.17.2
- osfi_b13: B-13.2.5, B-13.3.4, B-13.3.5
- finma_circular: IV.A(41), IV.D(75), IV.D(76), IV.D(77)
- gdpr: Art.32(1)(d), Art.33(5)
- dora: Art.17(2), Art.24(1)
- bio2: 5.24, 5.27
- rbi_csf: Annex1.19, ITGRCA.27
- fisc: FISC.O4
- lgpd_bcb: BCB.Art.5
- hkma_tme1: TME1.6.3, TME1.7.5
- dnb_good_practice: DNB.11.2
- cbb_tm: TM-13
- cbuae: CR-9
- nca_ecc: 2-13
- qatar_nia: IM
- sama_csf: 3.6
- uae_ia: T11
- bog_cisd: CISD-VII, CISD-X
- bom_ctrm: 5.1
- cbe_csf: CD-2
- cbn_csf: Part3.6, Part3.8
- sa_js2: JS2-7.4
- bot_cyber: Ch4.1
- cpmi_pfmi: CG.RR, CG.TE, PFMI.P17
- eba_ict: 3.5(d), 3.7.4
- ecb_croe: CROE.2.5.1, CROE.2.6.1
- ffiec_is: III.D
- hipaa_sr: §164.308(a)(6)(i)
- iosco_cyber: RR-1, RR-5, TEST-1, TEST-4
- nydfs_500: 500.16
- sebi_cscrf: CCMP, RS.MA
- cmmc_2: IR
- doe_c2m2: RESPONSE
- cbest: CBEST.10
- tiber_eu: TIBER.BT, TIBER.CLOSE
- fda_cyber: INC-1
- hitrust_csf: 11.a
- iso_27799: 16.1
- lloyds_ms: CRM.3, MS8.5, MS9.2
- naic_ds: 4F-a
- nhs_dspt: NDG-6.1
- solvency_ii: EIOPA-ICT-4.9
- csa_ccm_v4: BCR-10, SEF-04
- csa_aicm: BCR-10, SEF-04
- ccss_v9: 1.06.3
- sec_custody_digital: SEC-CD-11
OSA's mapping for iso_27001_2022 and nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/IR-03
- Clauses only: /api/v1/controls/IR-03?fields=mappings
- Page for people: /controls/ir-03/
