Quick-reference card
| Field | Value |
|---|---|
| Control ID | IR-04 |
| Control Name | Incident Handling |
| Framework | NIST SP 800-53 Revision 5 |
| Control Family | Incident Response |
| Baselines | LOW, MODERATE, HIGH, PRIVACY |
| Relevance | First Party and Third Party |
| Risk Severity | Critical |
What this control requires
IR-04 requires organizations to implement a repeatable incident handling capability covering preparation, detection, containment, eradication, and recovery. That capability must align with your documented incident response plan and produce consistent results regardless of which team or business unit is involved.
In practice, this means you need defined processes for detecting and analyzing security events, containing active threats, eradicating root causes, and recovering affected systems. You also need to coordinate these activities with your contingency planning program so that incident response and business continuity don’t operate in silos.
What makes this control stick, though, is its feedback loop. Lessons learned from each incident must flow back into your response procedures, your training curriculum, and your testing exercises. Without that loop, organizations repeat the same mistakes and their incident handling maturity stagnates. IR-04 sets the expectation that handling rigor, intensity, and scope are comparable across every part of the organization, not just the teams that respond most frequently.
Why it matters
Incident handling sits at the center of your security operations. When an organization can’t demonstrate a structured, repeatable approach to handling incidents, auditors flag it as a systemic weakness, and the downstream consequences extend well beyond a single finding.
Failure to maintain IR-04 introduces audit risk and may result in certification withdrawal or regulatory findings. For organizations operating under FedRAMP, FISMA, or similar federal frameworks, a gap in incident handling capability can stall or revoke an authorization to operate. Even outside government mandates, frameworks like NIST SP 800-53 treat IR-04 as a baseline control at every impact level, which means assessors expect mature evidence regardless of system categorization.
The risk compounds when incidents aren’t coordinated with contingency planning. An organization that handles a ransomware event without triggering its continuity plan may recover the compromised system but lose critical business processes in the gap. That disconnect turns a contained security event into an operational failure.
The damage compounds further when the lessons-learned cycle breaks down. Organizations that don’t update procedures after incidents leave the same vulnerabilities in place for the next event, and they can’t demonstrate continuous improvement to auditors reviewing their incident response program.
What attackers exploit:
- Inconsistent detection coverage across business units, allowing lateral movement through unmonitored segments
- Lack of documented containment procedures, which slows response and extends attacker dwell time
- Missing coordination between incident response and contingency planning, creating recovery blind spots
- Stale response procedures that haven’t incorporated lessons from prior incidents, leaving known attack patterns unaddressed
- Unpracticed response teams that default to ad hoc actions during high-pressure events
How to implement
Most organizations don’t fail IR-04 because they lack an incident response plan. They fail because their handling capability hasn’t been exercised and their lessons learned don’t feed back into procedures. Response quality ends up varying across teams as a result.
For your organization
Start by mapping your incident handling capability to the five required phases: preparation, detection and analysis, containment, eradication, and recovery. Each phase needs documented procedures and assigned roles, with clear escalation criteria that responders can act on without ambiguity.
Preparation goes beyond writing a plan. You need communication channels, contact rosters, forensic tool access, and pre-authorized containment actions that responders can execute without waiting for approvals during an active incident. Establish relationships with external parties you may need, including legal counsel, law enforcement contacts, and cyber incident reporting channels.
Detection and analysis requires defined sources and triage criteria. Pull from audit logs, network monitoring, endpoint detection, physical access systems, and user reports. Establish severity classification criteria so your team applies consistent triage across events rather than relying on individual judgment.
Containment, eradication, and recovery should be documented as decision trees, not open-ended guidelines. Define short-term containment actions, evidence preservation steps, root cause analysis procedures, and recovery validation criteria. Coordinate recovery steps with your contingency plan so that business continuity activates when incidents cross defined thresholds.
Lessons learned is where most organizations fall short. After every significant incident, conduct a structured review. Document what worked, what failed, and what needs to change. Then actually update your response procedures, your incident response training materials, and your test scenarios. Track these changes as formal updates with version control.
Consistency across the organization means standardized playbooks, centralized incident tracking, and regular tabletop exercises that include teams outside your security operations center. Common mistakes include maintaining a strong capability in one division while leaving others with outdated or untested procedures.
Evidence you should produce includes incident response policy documents, completed after-action reports, updated procedure versions with change logs, training records, and exercise results demonstrating cross-organizational consistency.
For your vendors
When assessing a vendor’s IR-04 compliance, your goal is to verify they have a functioning incident handling capability, not just a policy document sitting in a shared drive.
Questionnaire questions to include:
- Do you maintain a documented incident handling capability that covers preparation, detection, containment, eradication, and recovery?
- How do you coordinate incident response with business continuity and contingency planning?
- Describe your process for incorporating lessons learned from incidents into your response procedures and training.
- How do you ensure consistent incident handling quality across different teams, locations, or business units?
- What is your average time from detection to containment for security incidents in the past 12 months?
Evidence to request:
- Incident response plan with version history showing recent updates
- After-action reports or post-incident review summaries (redacted as needed) from the past year
- Training records showing incident response training completion across relevant staff
- Exercise or tabletop test results from the past 12 months
- Metrics on incident handling consistency, such as mean time to detect and mean time to contain
Red flags to watch for:
- An incident response plan that hasn’t been updated in over a year
- No evidence of post-incident reviews or lessons-learned sessions
- Inability to provide metrics on response times or incident volume
- Incident handling procedures that exist only at a corporate level with no evidence of operational adoption across business units
- No coordination mechanism between incident response and contingency planning teams
Verification approach: Request a walkthrough of a recent (redacted) incident to confirm the vendor followed their documented procedures. Compare the timeline against their stated processes. If the vendor can’t provide any incident examples, ask for their most recent tabletop exercise results instead.
Evidence examples
| Evidence Type | Example Artifact |
|---|---|
| Policy documentation | Incident response policy defining handling phases, roles, escalation paths, and coordination requirements with contingency planning |
| Response procedures | Phase-specific playbooks for detection and analysis, containment, eradication, and recovery with decision trees and checklists |
| After-action reports | Post-incident review documents capturing timeline, root cause analysis, response effectiveness, and recommended procedure changes |
| Training records | Completion logs for incident response training covering all phases of the handling lifecycle, updated to reflect lessons learned |
| Exercise results | Tabletop exercise reports and functional test results demonstrating cross-organizational incident handling consistency |
| Lessons-learned tracking | Change log showing procedure, training, and test-plan updates traced to specific incident findings |
| Coordination evidence | Records of contingency plan activation criteria and joint coordination procedures between incident response and business continuity teams |
Cross-framework mapping
| Framework | Control(s) | Coverage |
|---|---|---|
| ISO 27001:2022 | 5.25 Assessment and decision on information security events | Partial |
| ISO 27001:2022 | 5.26 Response to information security incidents | Partial |
| ISO 27001:2022 | 5.27 Learning from information security incidents | Partial |
| NIST SP 800-171 Rev 3 | 03.06.01 Incident Handling | Partial |
Related controls
- AC-19 — Access Control for Mobile Devices: defines access restrictions for mobile devices that may be vectors in incident detection and containment procedures
- AU-06 — Audit Record Review, Analysis, and Reporting: provides the audit data that feeds IR-04’s detection and analysis phase
- AU-07 — Audit Record Reduction and Report Generation: supports incident analysis by reducing large audit datasets into actionable reports
- CM-06 — Configuration Settings: establishes baseline configurations that incident handlers reference during eradication and recovery
- CP-02 — Contingency Plan: the continuity plan that IR-04 requires you to coordinate with during incident handling
- CP-03 — Contingency Training: training that must incorporate lessons learned from IR-04 incident handling activities
- CP-04 — Contingency Plan Testing: testing activities that should reflect incident handling scenarios and lessons learned
- IR-02 — Incident Response Training: the training program that IR-04’s lessons-learned cycle must feed updates into
- IR-03 — Incident Response Testing: the test exercises that validate whether IR-04’s handling capability works in practice
- IR-05 — Incident Monitoring: the ongoing monitoring that tracks incident trends and informs IR-04’s detection phase
Frequently asked questions
What is NIST SP 800-53 IR-04
IR-04 requires organizations to implement an incident handling capability that spans preparation, detection and analysis, containment, eradication, and recovery. It mandates coordination with contingency planning, a lessons-learned feedback loop into procedures and training, and consistent handling rigor across all organizational units. The control appears in LOW, MODERATE, HIGH, and PRIVACY baselines, making it a universal requirement across all four baseline impact levels.
What happens if IR-04 is not implemented
Without IR-04, your organization lacks a structured incident handling capability, which means incidents are handled ad hoc with inconsistent containment, eradication, and recovery outcomes. Auditors will flag the absence of after-action reports, lessons-learned updates to response procedures, and evidence of cross-organizational handling consistency. For federal systems, this gap can lead to authorization withdrawal. For organizations pursuing NIST-aligned certifications, it creates a critical finding that blocks compliance attestation.
How do you audit IR-04
Auditors verify that your incident handling capability is consistent with your incident response plan and covers all five required phases. They’ll review after-action reports for evidence that lessons learned have been incorporated into updated procedures, training materials, and test scenarios. They also assess whether handling rigor, intensity, scope, and results are comparable and predictable across different parts of the organization by examining incident tracking records, exercise results, and coordination documentation between incident response and contingency planning teams.
Does IR-04 apply to cloud-hosted systems
Yes, IR-04 applies to any system operating under NIST SP 800-53 baselines, including cloud-hosted environments. The control requires that incident handling rigor, intensity, and scope remain consistent whether your systems run on-premises, in a public cloud, or in a hybrid configuration. For cloud environments, this means your incident response plan must account for shared responsibility boundaries, define how your team coordinates containment and eradication with your cloud service provider, and ensure that forensic evidence collection procedures work within the provider’s infrastructure constraints.