Back to Control Explorer



Control Acronym



Incident Response

CMMC Level


800-171 Control #


CMMC Description

Test the organizational incident response capability.

CMMC Clarification

Testing an organization’s incident response capability validates existing plans as well as highlight lapses or changes within the environment. The test should seek to address questions like what happens during an incident, who is responsible for incident management, what tasks are assigned within the IT organization, what support would be needed from legal, public affairs, or other business component, how are resources obtained if needed during the incident, and how is law enforcement involved. Any negative impacts to the normal day-to-day mission when responding to an incident should also be identified and documented. Example As CISO, you decide to conduct an incident response table top exercise. The exercise plans to simulate an attacker gaining access to the network through a compromised server. When scheduling the exercise you include relevant IT staff such as security, database, network, and system administrators. You also request a representative from legal, HR, and the communications department. As the exercise begins you provide a scenario to the team. You have key questions aligned with the response plans to guide the exercise. During the exercise you focus on how the team executes the organization’s incident response plan. At the end of the test, you conduct a debrief with everyone that was involved to provide feedback and develop improvements to the incident response plan.

800-171 Description

Test the organizational incident response capability.

800-171 Discussion

Organizations test incident response capabilities to determine the effectiveness of the capabilities and to identify potential weaknesses or deficiencies. Incident response testing includes the use of checklists, walk-through or tabletop exercises, simulations (both parallel and full interrupt), and comprehensive exercises. Incident response testing can also include a determination of the effects on organizational operations (e.g., reduction in mission capabilities), organizational assets, and individuals due to incident response. [SP 800-84] provides guidance on testing programs for information technology capabilities.

Other Source Discussion


CIS Control References

CIS Controls v7.1 19.7

NIST 800-53 Control Ref.

NIST SP 800-53 Rev 4 IR-3

CMMC Derived

NIST CSF Control References

NIST 800-171 References

NIST SP 800-171 Rev 1 3.6.3

Applicable FAR Clause

NIST CSF Control Reference


CERT RMM Reference

Modification of NIST 800-171B Reference

NIST 800-171B Reference

UK NCSCCyber Reference

AS ACSC Reference


Assessment Sub-Criteria 1

IR.3.099.[a] the incident response capability is tested.

Assessment Sub-Criteria 2

IR.3.099.[a] the incident response capability is tested.

Assessment Sub-Criteria 3

Assessment Sub-Criteria 4

Assessment Sub-Criteria 5

Assessment Sub-Criteria 6

Assessment Sub-Criteria 7

Assessment Sub-Criteria 8

Assessment Sub-Criteria 9

Assessment Sub-Criteria 10

Assessment Sub-Criteria 11

Assessment Sub-Criteria 12

Assessment Sub-Criteria 13

Assessment Sub-Criteria 14

Assessment Sub-Criteria 15