
RC.CO-3: Communications
Recovery activities are communicated to internal and external stakeholders as well as executive and management teams.





RC.RP-1: Recovery Planning
Recovery plan is executed during or after a cybersecurity incident.


RS.MI-3: Mitigation
Newly identified vulnerabilities are mitigated or documented as accepted risks.



RS.AN-5: Analysis
Processes are established to receive, analyze and respond to vulnerabilities disclosed to the organization from internal and external sources (e.g., internal testing, security bulletins, or security researchers).





RS.CO-5: Communications
Voluntary information sharing occurs with external stakeholders to achieve broader cybersecurity situational awareness.

RS.CO-4: Communications
Coordination with stakeholders occurs consistent with response plans.



RS.CO-1: Communications
Personnel know their roles and order of operations when a response is needed.