7.3 Incident Response and Contingency Activities in Sustained Compliance
Key Takeaways
- Incident response and contingency planning are ongoing compliance obligations under Domain 7, not one-time implementation activities completed before authorization.
- NIST SP 800-61 Rev. 3, finalized in April 2025, supersedes Revision 2 and reframes incident response around the CSF 2.0 Functions rather than the four-phase handling cycle.
- Federal agencies report incidents to CISA within one hour of identification, and major incidents to Congress within seven days.
- Contingency planning is driven by a business impact analysis that establishes recovery time and recovery point objectives before any recovery strategy is selected.
- Incidents and contingency test results are continuous monitoring inputs: an incident that reveals a control failure generates a POA&M item and may trigger reauthorization.
Incident Response and Contingency Activities in Sustained Compliance
Within Domain 7's ongoing compliance activities, the blueprint requires that "incident response and contingency activities [be] performed." The placement matters: these are not build-phase tasks that finish at authorization. They are recurring obligations whose execution — and whose evidence — an assessor examines throughout the operational life of the system.
1. Current NIST Incident Response Guidance
NIST SP 800-61 Revision 3, finalized in April 2025, supersedes Revision 2 and restructures incident response as an element of cybersecurity risk management aligned to the CSF 2.0 Functions, rather than as a standalone handling process. Its organizing model groups activities into preparation (Govern, Identify, Protect) and incident response proper (Detect, Respond, Recover), with continuous improvement running throughout.
The Revision 2 four-phase lifecycle remains the vocabulary most study material uses, and it maps cleanly onto the newer structure:
| SP 800-61 Rev. 2 Phase | Activities | CSF 2.0 Alignment |
|---|---|---|
| Preparation | Plans, tooling, training, communication paths, retainers | Govern, Identify, Protect |
| Detection & Analysis | Identify events, triage, scope, categorize, prioritize | Detect |
| Containment, Eradication & Recovery | Limit spread, remove the cause, restore service | Respond, Recover |
| Post-Incident Activity | Lessons learned, evidence retention, control improvement | Govern (feeds back) |
Know both. The exam may use either framing, and the substantive obligations are the same.
Governing Controls
IR-1 (policy and procedures), IR-2 (training), IR-3 (testing), IR-4 (handling), IR-5 (monitoring), IR-6 (reporting), IR-7 (assistance), and IR-8 (the Incident Response Plan). Note the structure: an approved plan, trained people, and tested procedures are each separately required. A well-written plan that nobody has trained on or exercised satisfies IR-8 and fails IR-2 and IR-3.
2. Reporting Timelines
Reporting obligations are external, time-bound, and heavily examinable. Missing a notification deadline is a compliance violation independent of how well the incident itself was handled.
| Regime | Who Is Notified | Deadline |
|---|---|---|
| CISA (federal agencies) | CISA | Within 1 hour of identification by the agency's SOC/CSIRT |
| FISMA major incident | Congress | Within 7 days of identification |
| GDPR Art. 33 | Supervisory authority | Within 72 hours of becoming aware, unless unlikely to risk rights and freedoms |
| GDPR Art. 34 | Affected data subjects | Without undue delay, where high risk to their rights and freedoms |
| HIPAA Breach Notification | Affected individuals | Without unreasonable delay, no later than 60 days |
| HIPAA (500+ individuals) | HHS and prominent media | Within 60 days; smaller breaches reported annually |
[!IMPORTANT] The clock starts at awareness, not at certainty. GDPR's 72 hours runs from becoming aware of the breach, not from completing the investigation. Article 33 explicitly permits notifying in phases where information is not all available at once. Waiting until the full scope is understood is the most common way organizations miss the deadline — and it is a distractor the exam uses.
The major incident determination for federal agencies follows current OMB criteria, and the agency is ultimately responsible for making that determination, consulting CISA where helpful. This is a governance judgment with statutory consequences, which is why it belongs to the agency rather than to the SOC.
3. Contingency Planning
NIST SP 800-34 Rev. 1 governs contingency planning for information systems, and the exam expects you to distinguish the plan family.
| Plan | Scope |
|---|---|
| Business Continuity Plan (BCP) | Sustaining business functions during and after disruption |
| Continuity of Operations (COOP) | Sustaining an organization's essential functions at an alternate site |
| Information System Contingency Plan (ISCP) | Recovery of a specific information system |
| Disaster Recovery Plan (DRP) | IT recovery at an alternate site after a major disruption |
| Cyber Incident Response Plan | Response to a cyber incident specifically |
| Occupant Emergency Plan (OEP) | Life safety and building evacuation |
The Business Impact Analysis Drives Everything
The BIA precedes strategy selection. It identifies essential mission functions, maps the resources they depend on, and establishes the recovery metrics that determine what solution is required:
| Metric | Meaning | Determines |
|---|---|---|
| MTD / MAO | Maximum tolerable downtime before unacceptable consequences | The outer bound on all recovery planning |
| RTO | Recovery time objective — target for restoring service | The recovery site strategy |
| RPO | Recovery point objective — tolerable data loss measured in time | The backup and replication strategy |
| WRT | Work recovery time — verifying and reconciling before resuming | RTO + WRT must fit within MTD |
The relationship is causal and directional: RPO drives backup frequency; RTO drives recovery site capability. An RPO of one hour cannot be met by nightly backups regardless of how fast the recovery site is, and an RTO of four hours cannot be met by a cold site regardless of how frequent the backups are. Exam items commonly pair a stated objective with an incompatible technical solution.
Site options run cold (space and utilities only, days to activate), warm (equipment and connectivity, hours), hot (fully operational with current data, minutes to hours), and mirrored/active-active (effectively immediate), with cost rising accordingly.
Testing Is a Recurring Obligation
CP-4 requires contingency plan testing, and the type governs what is actually proven:
| Test Type | Method | Proves |
|---|---|---|
| Tabletop | Discussion-based walkthrough | Plan logic and role understanding |
| Functional | Exercise specific capabilities (e.g. restore from backup) | That components actually work |
| Full-scale / full interruption | Failover to the alternate site | End-to-end recovery capability |
Frequency and rigor scale with impact level, and higher-impact systems face more demanding requirements. The recurring finding this addresses is untested backups: an organization that has never performed a restore does not know whether its backups are recoverable, and CP-4 exists precisely to convert that assumption into evidence.
4. Feeding Results Back Into the Risk Cycle
The compliance value of incident and contingency activity is realized in the feedback loop, and this is where Domain 7 connects to the rest of the framework:
- Lessons learned identify control deficiencies. Those become POA&M items and may require SSP updates.
- An incident revealing a control failure is direct evidence that a control assessed as satisfied is not operating as intended — which changes the system's risk posture and is reported to the Authorizing Official.
- A significant incident may trigger reauthorization, because it invalidates assumptions the original authorization relied upon.
- Incident data is a continuous monitoring input, feeding the metrics and frequencies of the ISCM strategy.
- Test failures are findings. A contingency test that fails to meet the RTO is a deficiency requiring remediation, not merely a lesson noted.
[!NOTE] Evidence discipline. Assessors examine incident tickets with timestamps, notification records demonstrating deadlines were met, after-action reports, contingency test plans and results with participants and dates, training completion records, and evidence that identified improvements were actually implemented. The last item is what distinguishes a functioning programme: organizations that run exercises, document findings, and never act on them produce the same findings year after year.
A European subsidiary's security team becomes aware on Monday morning that customer personal data has probably been exposed, but the forensic investigation will take another week to establish the full scope. Under GDPR Article 33, when must the supervisory authority be notified?
A system's business impact analysis establishes a recovery point objective of one hour. The organization maintains a hot site capable of assuming operations within 30 minutes but backs the system up nightly. Can the objectives be met?
A post-incident review determines that an incident succeeded because an access control assessed as satisfied during authorization was not actually operating as intended in production. What is the correct governance response?