Skip to content

Incident Response

Incident Response is your breach playbook. When — not if — something goes wrong, these requirements ensure you can detect it, contain it, report it, and recover.

Plan (3.6.1) — A documented IR capability covering preparation, detection, analysis, containment, recovery, and communication — including the 72-hour DoD reporting requirement.

Execute (3.6.2) — Track every incident from detection through closure. Report internally and externally as required.

Improve (3.6.3) — Test the plan at least annually with tabletop exercises. Document findings and update the plan.


RefShort NameWhat It Covers
3.6.1Have a PlanDocumented IR capability with all six phases
3.6.2Track and ReportIncident tracking, documentation, and DIBCAC reporting
3.6.3Test the PlanAnnual tabletop exercises with documented improvements