# IR-05 Incident Monitoring

NIST SP 800-53 control. Family: IR Incident Response. Function: corrective. Baselines: low, moderate, high, privacy. Mapping licence: CC BY-SA 4.0.

Statement: Track and document incidents.
Guidance: Documenting incidents includes maintaining records about each incident, the status of the incident, and other pertinent information necessary for forensics as well as evaluating incident details, trends, and handling. Incident information can be obtained from a variety of sources, including network monitoring, incident reports, incident response teams, user complaints, supply chain partners, audit monitoring, physical access monitoring, and user and administrator reports. IR-04 provides information on the types of incidents that are appropriate for monitoring.

## Enhancements (1)
- IR-05(01) Automated Tracking, Data Collection, and Analysis. Baselines: high
Each enhancement's statement: /api/v1/controls/IR-05?fields=enhancements

## Patterns that use it (11)
- Critical (3): SP-025 Advanced Monitoring and Detection; SP-031 Security Monitoring and Response; SP-036 Incident Response
- Important (8): SP-001 Client Module; SP-002 Server Module; SP-006 Wireless- Private Network Pattern; SP-007 Wireless- Public Hotspot Pattern; SP-023 Industrial Control Systems; SP-029 Zero Trust Architecture; SP-030 API Security; SP-043 Security Metrics and Measurement

## Clauses by framework (69 frameworks)
- iso_27001_2022: A.5.25. OSA's own, not in NIST's crosswalk: A.5.25
- iso_27002_2022: 5.25, 5.26
- cobit_2019: DSS02, DSS03
- pci_dss_v4: 12.10
- nist_csf_2: DE.AE-03, DE.AE-08, RS.AN-08, RS.MA-02, RS.MA-03, RS.MA-04. OSA's own, not in NIST's crosswalk: DE.AE-08, RS.AN-08
- cis_controls_v8: CIS 17, CIS 17.9
- soc2_tsc: CC7.4, CC7.4-POF6
- finos_ccc: CCC-C15
- iso_42001_2023: A.8.4
- nis2: Art. 21(2)(b)
- bsi_grundschutz: DER.1, DER.2.1
- anssi: Hygiene.29, Hygiene.39, SecNumCloud.17.1
- osfi_b13: B-13.2.5, B-13.3.3
- finma_circular: IV.A(41), IV.A(44), IV.C(66), IV.C(67)
- gdpr: Art.33(3)(d), Art.33(5)
- dora: Art.17(3)(c), Art.18(1)
- bio2: 5.25, 5.26
- rbi_csf: Annex1.19, ITGRCA.27
- fisc: FISC.O4
- lgpd_bcb: BCB.Art.5, BCB.Art.5-Supp, BCB.Art.7, LGPD.Art.48
- hkma_tme1: TME1.5.4, TME1.7.5
- mlps_2: 8.1.5.4, 8.1.10.10
- dnb_good_practice: DNB.15.2
- cra: CRA.Art14
- swift_cscf: SWIFT.7.1
- cbb_tm: TM-13
- cbuae: CR-9
- nca_ecc: 2-13
- qatar_nia: IM
- sama_csf: 3.6
- uae_ia: T11
- bog_cisd: CISD-VII
- bom_ctrm: 5.1, 5.3
- cbe_csf: CD-2
- cbn_csf: Part3.6
- popia: s22
- sa_js2: JS2-7.4
- bot_cyber: Ch4.1
- cpmi_pfmi: CG.LE, CG.RR, PFMI.P17
- eba_ict: 3.5(d)
- ecb_croe: CROE.2.5.1, CROE.2.8.1
- ffiec_is: III.C, III.D
- hipaa_sr: §164.308(a)(6)(i), §164.308(a)(6)(ii)
- iosco_cyber: LE-1, RR-1
- nydfs_500: 500.16
- sebi_cscrf: RS.AN, RS.IM, RS.MA, SOC
- cmmc_2: IR
- nerc_cip: CIP-008-6
- doe_c2m2: RESPONSE, SITUATION
- api_1164: Sec 10
- awia: AWWA Sec 5, AWWA Sec 6
- iaea_nss: Sec 7
- cbest: CBEST.5
- tiber_eu: TIBER.BT, TIBER.CLOSE
- fda_cyber: INC-1, INC-2, VR-1
- hitrust_csf: 11.a, 11.b
- iso_27799: 16.2
- lloyds_ms: MS8.5
- naic_ds: 4F-a, 5
- nhs_dspt: NDG-6.1, NDG-6.3
- solvency_ii: EIOPA-ICT-4.9
- csa_ccm_v4: SEF-06
- csa_aicm: SEF-06
- ccss_v9: 1.02.8
- mica: Art.62(8)
- basel_sco60: SCO60.23, SCO60.55, SCO60.73
- bssc: GSP-05
- sec_custody_digital: SEC-CD-11
- dpdpa: Rules.7(2)
OSA's mapping for iso_27001_2022 and nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/IR-05
- Clauses only: /api/v1/controls/IR-05?fields=mappings
- Page for people: /controls/ir-05/
