# RS — Respond

- **Function ID:** RS

## Subcategories

- [RS.AN-03](/md/csf/RS.AN-03.md) — Analysis is performed to establish what has taken place during an incident and the root cause of the incident
- [RS.AN-06](/md/csf/RS.AN-06.md) — Actions performed during an investigation are recorded, and the records' integrity and provenance are preserved
- [RS.AN-07](/md/csf/RS.AN-07.md) — Incident data and metadata are collected, and their integrity and provenance are preserved
- [RS.AN-08](/md/csf/RS.AN-08.md) — An incident's magnitude is estimated and validated
- [RS.CO-02](/md/csf/RS.CO-02.md) — Internal and external stakeholders are notified of incidents
- [RS.CO-03](/md/csf/RS.CO-03.md) — Information is shared with designated internal and external stakeholders
- [RS.MA-01](/md/csf/RS.MA-01.md) — The incident response plan is executed in coordination with relevant third parties once an incident is declared
- [RS.MA-02](/md/csf/RS.MA-02.md) — Incident reports are triaged and validated
- [RS.MA-03](/md/csf/RS.MA-03.md) — Incidents are categorized and prioritized
- [RS.MA-04](/md/csf/RS.MA-04.md) — Incidents are escalated or elevated as needed
- [RS.MA-05](/md/csf/RS.MA-05.md) — The criteria for initiating incident recovery are applied
- [RS.MI-01](/md/csf/RS.MI-01.md) — Incidents are contained
- [RS.MI-02](/md/csf/RS.MI-02.md) — Incidents are eradicated

---

Derived from official NIST publications (NIST SP 800-53 Rev 5 and NIST CSF 2.0). nistcontrols.com is not affiliated with NIST.
