Skip to content
Browse docs

Incident Response — FedRAMP KSI Domain

Generated from the official FedRAMP/rules GitHub repo. Source path: fedramp-consolidated-rules.json on main at blob 7d628b63fdd9. Consolidated Rules version: 2026.07.02.02 · upstream last_updated: 2026-07-02. Supporting narrative documentation is available from the official FedRAMP/2026-markdown repository.

Incident Response

Domain code: INR · Domain ID: KSI-INR · Web slug: incident-response

Indicators

KSI-INR-AAR — Generating After Action Reports

Incident after action reports are generated and lessons learned are persistently incorporated.

Mapped Rev5 controls: ir-3, ir-4, ir-4.1, ir-8

Terms: Incident, Persistently

Recent update: 2026-06-24 — Official launch of the FedRAMP Consolidated Rules for 2026.

KSI-INR-RIR — Reviewing Incident Response Procedures

The effectiveness of documented incident response procedures is persistently reviewed.

Mapped Rev5 controls: ir-4, ir-4.1, ir-6, ir-6.1, ir-6.3, ir-7, ir-7.1, ir-8, ir-8.1, si-4.5

Terms: Incident, Persistently, Vulnerability Response

Recent update: 2026-06-24 — Official launch of the FedRAMP Consolidated Rules for 2026.

KSI-INR-RPI — Reviewing Past Incidents

Past incidents are persistently reviewed for patterns or vulnerabilities that were not previously apparent or identified.

Mapped Rev5 controls: ir-3, ir-4, ir-4.1, ir-5, ir-8

Terms: Incident, Persistently, Vulnerability

Recent update: 2026-06-24 — Official launch of the FedRAMP Consolidated Rules for 2026.

URL copied to clipboard