# IR-07 Incident Response Assistance

NIST SP 800-53 control. Family: IR Incident Response. Function: corrective. Baselines: low, moderate, high, privacy. Mapping licence: CC BY-SA 4.0.

Statement: Provide an incident response support resource, integral to the organizational incident response capability, that offers advice and assistance to users of the system for the handling and reporting of incidents.
Guidance: Incident response support resources provided by organizations include help desks, assistance groups, automated ticketing systems to open and track incident response tickets, and access to forensics services or consumer redress services, when required.

## Enhancements (2)
- IR-07(01) Automation Support for Availability of Information and Support. Baselines: moderate, high
- IR-07(02) Coordination with External Providers
Each enhancement's statement: /api/v1/controls/IR-07?fields=enhancements

## Patterns that use it (9)
- Important (1): SP-036 Incident Response
- Standard (8): SP-001 Client Module; SP-002 Server Module; SP-006 Wireless- Private Network Pattern; SP-007 Wireless- Public Hotspot Pattern; SP-019 Secure Ad-Hoc File Exchange Pattern; SP-021 Realtime Collaboration Pattern; SP-023 Industrial Control Systems; SP-031 Security Monitoring and Response

## Clauses by framework (56 frameworks)
- iso_27001_2022: 7.4, A.5.26, A.6.8. OSA's own, not in NIST's crosswalk: 7.4, A.5.26, A.6.8
- iso_27002_2022: 5.24, 5.26, 6.8
- cobit_2019: DSS02
- pci_dss_v4: 12.10
- nist_csf_2: GV.RM-05, RC.CO-03, RC.CO-04, RS.CO-02, RS.CO-03, RS.MA-01, RS.MA-04. OSA's own, not in NIST's crosswalk: GV.RM-05, RC.CO-03, RC.CO-04
- cis_controls_v8: CIS 17, CIS 17.2, CIS 17.6
- iso_42001_2023: A.8.4
- nis2: Art. 21(2)(b), Art. 23
- pra_op_resilience: SS1/21-8.1
- anssi: Hygiene.40, Hygiene.42, SecNumCloud.17.1
- osfi_b13: B-13.2.5, B-13.3.4
- finma_circular: IV.A(41), IV.C(70), IV.D(71)
- gdpr: Art.33(1), Art.34(1), Art.34(2)
- dora: Art.11(7), Art.14, Art.17(3)(d), Art.22(1)
- bio2: 5.24, 5.26, 6.8
- rbi_csf: Annex1.19, ITGRCA.27
- fisc: FISC.O4
- lgpd_bcb: BCB.Art.5, BCB.Art.7, LGPD.Art.48
- hkma_tme1: TME1.5.4, TME1.7.5
- cra: CRA.II.6
- cbb_tm: TM-13
- cbuae: CR-9
- nca_ecc: 2-13
- qatar_nia: IM
- sama_csf: 3.6
- uae_ia: T11
- bog_cisd: CISD-VII
- bom_ctrm: 5.1
- cbe_csf: CD-2
- cbn_csf: Part3.6
- popia: s22
- sa_js2: JS2-7.4
- bot_cyber: Ch4.1
- cpmi_pfmi: CG.RR
- eba_ict: 3.5(d), 3.7.5, 3.8(d)
- ecb_croe: CROE.2.5.1, CROE.2.5.3
- ffiec_is: III.D
- hipaa_sr: §164.308(a)(6)(i), §164.308(a)(6)(ii)
- iosco_cyber: RR-1, RR-4
- nydfs_500: 500.16
- sebi_cscrf: RS.MA
- cmmc_2: IR
- tiber_eu: TIBER.BT
- isae_3402: Clause 10
- fda_cyber: 524B-3, CVD-1, INC-1
- hitrust_csf: 11.a
- iso_27799: 16.1
- lloyds_ms: MS8.5
- naic_ds: 4F-a
- nhs_dspt: NDG-6.1
- solvency_ii: EIOPA-ICT-4.9
- csa_ccm_v4: SEF-07
- csa_aicm: SEF-07
- mica: Art.62(8), Art.64(1)
- basel_sco60: SCO60.73
- sec_custody_digital: SEC-CD-11
OSA's mapping for iso_27001_2022 and nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/IR-07
- Clauses only: /api/v1/controls/IR-07?fields=mappings
- Page for people: /controls/ir-07/
