7.3 Incident Response and Contingency Activities in Sustained Compliance

Key Takeaways

  • Incident response and contingency planning are ongoing compliance obligations under Domain 7, not one-time implementation activities completed before authorization.
  • NIST SP 800-61 Rev. 3, finalized in April 2025, supersedes Revision 2 and reframes incident response around the CSF 2.0 Functions rather than the four-phase handling cycle.
  • Federal agencies report incidents to CISA within one hour of identification, and major incidents to Congress within seven days.
  • Contingency planning is driven by a business impact analysis that establishes recovery time and recovery point objectives before any recovery strategy is selected.
  • Incidents and contingency test results are continuous monitoring inputs: an incident that reveals a control failure generates a POA&M item and may trigger reauthorization.
Last updated: August 2026

Incident Response and Contingency Activities in Sustained Compliance

Within Domain 7's ongoing compliance activities, the blueprint requires that "incident response and contingency activities [be] performed." The placement matters: these are not build-phase tasks that finish at authorization. They are recurring obligations whose execution — and whose evidence — an assessor examines throughout the operational life of the system.


1. Current NIST Incident Response Guidance

NIST SP 800-61 Revision 3, finalized in April 2025, supersedes Revision 2 and restructures incident response as an element of cybersecurity risk management aligned to the CSF 2.0 Functions, rather than as a standalone handling process. Its organizing model groups activities into preparation (Govern, Identify, Protect) and incident response proper (Detect, Respond, Recover), with continuous improvement running throughout.

The Revision 2 four-phase lifecycle remains the vocabulary most study material uses, and it maps cleanly onto the newer structure:

SP 800-61 Rev. 2 PhaseActivitiesCSF 2.0 Alignment
PreparationPlans, tooling, training, communication paths, retainersGovern, Identify, Protect
Detection & AnalysisIdentify events, triage, scope, categorize, prioritizeDetect
Containment, Eradication & RecoveryLimit spread, remove the cause, restore serviceRespond, Recover
Post-Incident ActivityLessons learned, evidence retention, control improvementGovern (feeds back)

Know both. The exam may use either framing, and the substantive obligations are the same.

Governing Controls

IR-1 (policy and procedures), IR-2 (training), IR-3 (testing), IR-4 (handling), IR-5 (monitoring), IR-6 (reporting), IR-7 (assistance), and IR-8 (the Incident Response Plan). Note the structure: an approved plan, trained people, and tested procedures are each separately required. A well-written plan that nobody has trained on or exercised satisfies IR-8 and fails IR-2 and IR-3.


2. Reporting Timelines

Reporting obligations are external, time-bound, and heavily examinable. Missing a notification deadline is a compliance violation independent of how well the incident itself was handled.

RegimeWho Is NotifiedDeadline
CISA (federal agencies)CISAWithin 1 hour of identification by the agency's SOC/CSIRT
FISMA major incidentCongressWithin 7 days of identification
GDPR Art. 33Supervisory authorityWithin 72 hours of becoming aware, unless unlikely to risk rights and freedoms
GDPR Art. 34Affected data subjectsWithout undue delay, where high risk to their rights and freedoms
HIPAA Breach NotificationAffected individualsWithout unreasonable delay, no later than 60 days
HIPAA (500+ individuals)HHS and prominent mediaWithin 60 days; smaller breaches reported annually

[!IMPORTANT] The clock starts at awareness, not at certainty. GDPR's 72 hours runs from becoming aware of the breach, not from completing the investigation. Article 33 explicitly permits notifying in phases where information is not all available at once. Waiting until the full scope is understood is the most common way organizations miss the deadline — and it is a distractor the exam uses.

The major incident determination for federal agencies follows current OMB criteria, and the agency is ultimately responsible for making that determination, consulting CISA where helpful. This is a governance judgment with statutory consequences, which is why it belongs to the agency rather than to the SOC.


3. Contingency Planning

NIST SP 800-34 Rev. 1 governs contingency planning for information systems, and the exam expects you to distinguish the plan family.

PlanScope
Business Continuity Plan (BCP)Sustaining business functions during and after disruption
Continuity of Operations (COOP)Sustaining an organization's essential functions at an alternate site
Information System Contingency Plan (ISCP)Recovery of a specific information system
Disaster Recovery Plan (DRP)IT recovery at an alternate site after a major disruption
Cyber Incident Response PlanResponse to a cyber incident specifically
Occupant Emergency Plan (OEP)Life safety and building evacuation

The Business Impact Analysis Drives Everything

The BIA precedes strategy selection. It identifies essential mission functions, maps the resources they depend on, and establishes the recovery metrics that determine what solution is required:

MetricMeaningDetermines
MTD / MAOMaximum tolerable downtime before unacceptable consequencesThe outer bound on all recovery planning
RTORecovery time objective — target for restoring serviceThe recovery site strategy
RPORecovery point objective — tolerable data loss measured in timeThe backup and replication strategy
WRTWork recovery time — verifying and reconciling before resumingRTO + WRT must fit within MTD

The relationship is causal and directional: RPO drives backup frequency; RTO drives recovery site capability. An RPO of one hour cannot be met by nightly backups regardless of how fast the recovery site is, and an RTO of four hours cannot be met by a cold site regardless of how frequent the backups are. Exam items commonly pair a stated objective with an incompatible technical solution.

Site options run cold (space and utilities only, days to activate), warm (equipment and connectivity, hours), hot (fully operational with current data, minutes to hours), and mirrored/active-active (effectively immediate), with cost rising accordingly.

Testing Is a Recurring Obligation

CP-4 requires contingency plan testing, and the type governs what is actually proven:

Test TypeMethodProves
TabletopDiscussion-based walkthroughPlan logic and role understanding
FunctionalExercise specific capabilities (e.g. restore from backup)That components actually work
Full-scale / full interruptionFailover to the alternate siteEnd-to-end recovery capability

Frequency and rigor scale with impact level, and higher-impact systems face more demanding requirements. The recurring finding this addresses is untested backups: an organization that has never performed a restore does not know whether its backups are recoverable, and CP-4 exists precisely to convert that assumption into evidence.


4. Feeding Results Back Into the Risk Cycle

The compliance value of incident and contingency activity is realized in the feedback loop, and this is where Domain 7 connects to the rest of the framework:

  • Lessons learned identify control deficiencies. Those become POA&M items and may require SSP updates.
  • An incident revealing a control failure is direct evidence that a control assessed as satisfied is not operating as intended — which changes the system's risk posture and is reported to the Authorizing Official.
  • A significant incident may trigger reauthorization, because it invalidates assumptions the original authorization relied upon.
  • Incident data is a continuous monitoring input, feeding the metrics and frequencies of the ISCM strategy.
  • Test failures are findings. A contingency test that fails to meet the RTO is a deficiency requiring remediation, not merely a lesson noted.

[!NOTE] Evidence discipline. Assessors examine incident tickets with timestamps, notification records demonstrating deadlines were met, after-action reports, contingency test plans and results with participants and dates, training completion records, and evidence that identified improvements were actually implemented. The last item is what distinguishes a functioning programme: organizations that run exercises, document findings, and never act on them produce the same findings year after year.

Loading diagram...
Incident and Contingency Activities in the Sustained Compliance Loop
Test Your Knowledge

A European subsidiary's security team becomes aware on Monday morning that customer personal data has probably been exposed, but the forensic investigation will take another week to establish the full scope. Under GDPR Article 33, when must the supervisory authority be notified?

A
B
C
D
Test Your Knowledge

A system's business impact analysis establishes a recovery point objective of one hour. The organization maintains a hot site capable of assuming operations within 30 minutes but backs the system up nightly. Can the objectives be met?

A
B
C
D
Test Your Knowledge

A post-incident review determines that an incident succeeded because an access control assessed as satisfied during authorization was not actually operating as intended in production. What is the correct governance response?

A
B
C
D