Skip to content
ControlVerdict
IR.L2-3.6.1CMMC Level 2Level 2

Incident Handling

Practice statement

Establish an operational incident-handling capability for organizational systems that includes preparation, detection, analysis, containment, recovery, and user response activities.

Quoted verbatim from NIST SP 800-171 Rev. 2 §3.6.1.Source

The source document’s non-normative “Discussion” section is not reproduced here. ControlVerdict quotes normative text verbatim or omits it — it never paraphrases a standard. Follow the source link above for the full context.

Assessment Objectives(7)

An assessor determines each objective separately. “Mostly implemented” is not a result — every objective below has to stand on its own.

  1. [a]

    an operational incident-handling capability is established;

    1 example covers this

  2. [b]

    the operational incident-handling capability includes preparation;

    1 example covers this

  3. [c]

    the operational incident-handling capability includes detection;

    1 example covers this

  4. [d]

    the operational incident-handling capability includes analysis;

    1 example covers this

  5. [e]

    the operational incident-handling capability includes containment;

    1 example covers this

  6. [f]

    the operational incident-handling capability includes recovery; and

    1 example covers this

  7. [g]

    the operational incident-handling capability includes user response activities.

    1 example covers this

Objective text quoted verbatim from NIST SP 800-171A via the CMMC Level 2 assessment guide.

Implementation examples(1)

Submit your own example
  • addresses
    IR.L2-3.6.1Incident Handling
    Establish an operational incident-handling capability for organizational systems that includes preparation, detection, analysis, containment, recovery, and user response activities.
    • [a]

      an operational incident-handling capability is established;
    • [b]

      the operational incident-handling capability includes preparation;
    • [c]

      the operational incident-handling capability includes detection;
    • [d]

      the operational incident-handling capability includes analysis;
    • [e]

      the operational incident-handling capability includes containment;
    • [f]

      the operational incident-handling capability includes recovery; and
    • [g]

      the operational incident-handling capability includes user response activities.

    Six-phase runbook with a severity ladder on-call can follow at 2 a.m.

    ControlVerdict Corpus@cv-corpusOSCJul 31, 2026
    Community is just starting — add yours. Only 2 verdicts so far.Last verdict Aug 2, 2026

    Implementation

    AO coverage. Addresses all Incident Handling objectives — an operational capability covering preparation, detection, analysis, containment, recovery, and user response activities.

    Preparation. A named incident commander and two backups, an on-call rotation with a paging tool, a severity ladder pinned to the first page of the runbook, pre-authorized containment actions (isolate an endpoint, disable an account, block a sender) that on-call may take without waking an executive, an out-of-band communication channel that does not depend on the identity provider we might be evicting an attacker from, and printed contact cards for legal, the customer, and the provider. Preparation also includes the boring part: the asset inventory and network diagram the responder will need at 2 a.m.

    Detection. Endpoint detections, identity risk events, and log-source alerts route to the paging tool with severity attached; the provider triages overnight and pages only on qualifying alerts. User reports arrive through a report-phish button and the help desk, and are treated as a detection source with the same intake path — several of our real incidents started there.

    Analysis. Every page opens a case record. The responder establishes scope (which identities, which hosts, what data), determines whether CUI is implicated — a question asked explicitly on every case because it drives external reporting — and records a timeline as they go rather than reconstructing it afterward. The severity ladder is re-evaluated after initial analysis; downgrades are as normal as upgrades.

    Containment. Pre-authorized actions first, then a containment decision by the incident commander weighing evidence preservation against spread. For identity compromise the standard play is revoke sessions, reset credentials, re-register authentication methods, and review what the account touched. Forensic images are taken before rebuild on any case where CUI exposure is plausible.

    Recovery. Restore from known-good, validate the entry vector is closed before returning to service, and monitor the affected scope at elevated sensitivity for a defined watch period. Recovery is declared by the incident commander, not by whoever finished their task first.

    User response activities. Users are told what to do (report, do not delete, do not investigate on your own), what will be asked of them, and what happens to their device. Affected users receive direct instructions during the incident; the workforce receives a short awareness note afterward when the lesson generalizes.

    Maintenance. After-action review within ten business days on every qualifying incident, with action items tracked in the plan of action. Runbook revised whenever an after-action finds it wrong.

    Accepted gap. We have no in-house forensic capability beyond memory and disk capture. Deep analysis is contracted to an incident response firm on retainer; the retainer, the engagement trigger, and the data-handling terms are documented so nobody negotiates a contract during an incident.

    What the evidence looks like

    • Incident response plan with the phase runbooks and the severity ladder
    • On-call rotation export and a sample page-to-acknowledgment timeline
    • Redacted case record showing scope, CUI determination, timeline, and containment decision
    • Pre-authorized containment action list approved by management
    • After-action report with tracked action items, and the response firm retainer

    Environment

    OSC of ~300 staff with no in-house 24x7 SOC. After-hours coverage is a three-person on-call rotation backed by a managed detection and response retainer.

    Tools

    2 ratings on this revision

    • BarelyControlVerdict Assessor@cv-assessorAug 2, 2026

      Across the finish line

      Plan exists and names roles.

      Gaps

      Want evidence of at least one tabletop or real incident after-action that exercised the plan.

    • AlignedControlVerdict Implementer@cv-implementerOSCAug 2, 2026

      Across the finish line

      Incident handling roles and communication path are clear enough to tabletop.

Discussion(0)

No discussion on this control yet

Edge cases, scoping questions, and “would this pass?” scenarios belong here.

Sign in to start a thread.