A.5.26 Organizational
Response to information security incidents
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (12)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- IR-4mostlyaligns with — Both controls require a structured, team-based process to contain, investigate, escalate, and close security incidents while coordinating with internal and external parties.
- IR-8mostlyaligns with — The ISO control's requirement to establish, communicate, and execute incident response procedures directly supports the NIST mandate for a documented incident response plan.
- IR-5partialaligns with — Logging all response activities and performing post-incident analysis provide the monitoring and tracking functions that IR-5 expects for incident oversight.
- IR-6partialaligns with — The ISO guidance to communicate incident details to relevant internal and external parties aligns with NIST's requirement for timely incident reporting.
- IR-9partialaligns with — Collecting evidence and conducting forensic analysis under the ISO control supports the information-spillage handling and evidence-preservation objectives of IR-9.
- SI-2partialaligns with — Identifying and remediating vulnerabilities or weaknesses revealed by the incident maps to the flaw-remediation activities required by SI-2.
Aligned NIST CSF 2.0 outcomes (15)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- RS.AN-03mostlyaligns with — Post-incident root-cause analysis and forensic examination are required by the ISO guidance and directly support the CSF analysis outcome.
- RS.CO-02mostlyaligns with — The ISO control mandates notifying internal and external stakeholders of incidents in accordance with the need-to-know principle.
- RS.CO-03mostlyaligns with — Coordination and information sharing with authorities, suppliers, clients, and other external parties are explicitly required to improve response effectiveness.
- RS.MA-01mostlyaligns with — Both require coordinated execution of the incident response plan with relevant third parties once an incident is declared.
- RS.MI-01mostlyaligns with — The ISO control explicitly directs containment actions to limit the spread of incident consequences, matching the CSF containment outcome.
- ID.RA-01partialaligns with — The ISO control requires identification and management of vulnerabilities and weaknesses that contributed to or failed to prevent the incident.
- RS.MA-05partialaligns with — Formal closure of the incident and transition to normal operations align with the CSF outcome that applies criteria for initiating recovery.
Related OWASP ASVS 5.0 requirements (6)
Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Related weaknesses / CWE (7)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-200partialmitigates — Evidence collection, need-to-know communication, and forensic analysis limit further exposure of sensitive information once an incident is detected.
- CWE-284partialfinds — Formal incident containment and post-incident root-cause analysis reduce the window during which improper access control flaws can be exploited and ensure discovered authorization weaknesses are corrected.
- CWE-508partialfinds — Incident-response procedures help contain and eradicate non-replicating malicious code.
- CWE-223nonenone — Incident response effectiveness is reduced without the omitted information.
- CWE-400nonedetects — Escalation procedures and business-continuity invocation help restore service availability after resource-exhaustion incidents.
- CWE-693nonenone — Identifying and remediating control weaknesses that contributed to an incident reduces the likelihood that protection mechanisms will fail again.
- CWE-778nonenone — Mandatory logging of all response activities and subsequent post-incident analysis directly address insufficient logging by ensuring security-relevant events are recorded and reviewed.
Mitigated MITRE ATT&CK techniques (5)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- T1486partialmitigates — Immediate containment and evidence collection reduce the time an adversary can maintain encryption processes before defenders intervene.
- T1565partialmitigates — Post-incident root-cause analysis and vulnerability remediation directly address the manipulation of stored or transmitted data that caused the incident.
- T1070nonemitigates — Forensic logging and evidence preservation requirements make it harder for attackers to erase traces without leaving detectable gaps in the incident record.
- T1485nonemitigates — Rapid containment procedures limit the blast radius of destructive actions that would otherwise erase or corrupt data across multiple systems.
- T1490nonemitigates — Escalation to business continuity plans and coordinated recovery actions reduce the impact of recovery-inhibiting techniques used during an incident.
Prevented OWASP Web Top 10 (2025) risks (3)
OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- A02partialmitigates — Post-incident root-cause work explicitly calls out control weaknesses and misconfigurations that allowed the incident, driving their remediation and thereby reducing future misconfiguration exposure.
- A08partialfinds — Forensic collection and analysis of evidence after an incident can reveal integrity failures in software or data, enabling targeted fixes that limit recurrence.
- A09partialmitigates — Mandating immediate, detailed logging of every response step and subsequent root-cause analysis directly supplies the evidence and visibility that security-logging failures otherwise leave missing.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.