Respond (RS): what it demands and how it is evidenced
Four categories covering the hours that decide breach outcomes: incident management, analysis, communication and mitigation. For Indian entities this function carries statutory weight — CERT-In’s 6-hour reporting window and sectoral timelines live inside RS.CO.
Reviewed by Tanya Kumari, Director — compliance assessment & certification readiness · Part of the CSF 2.0 series · CSF is voluntary guidance — we build profiles, not certificates
The categories inside Respond
Category identifiers reference NIST CSF 2.0 (26 February 2024) — nist.gov/cyberframework.
Where profiles fall short
RS.CO fails when the 6-hour CERT-In window is looked up during the breach; the reporting matrix (who, what, when, how) must pre-exist and be drilled.
Rebuilding a compromised host before imaging it satisfies RS.MI while destroying RS.AN — the runbook must sequence preservation before eradication where feasible.
Tabletops with lessons-learned records are the difference between a plan and a capability; every framework samples them.
Evidence that holds up
- Incident response plan with declaration-to-closure workflow (RS.MA)
- Forensic/evidence-handling procedure and sampled investigation records (RS.AN)
- Regulatory reporting matrix (CERT-In 6h, sectoral, DPDP) with drill evidence (RS.CO)
- Containment/eradication records from real incidents or exercises (RS.MI)
- Tabletop records with lessons feeding ID.IM
Respond FAQ
What are the Indian reporting obligations inside RS.CO?
CERT-In requires notified incident types reported within 6 hours; sector regulators add their own windows (e.g. RBI frameworks with 2–6 hour expectations), and DPDP Rule 7 adds intimation to affected data principals without delay plus detailed reporting to the Board within 72 hours.
Does Respond include deciding NOT to act?
Yes — prioritisation under RS.MA includes risk-based decisions to monitor rather than immediately contain, documented with rationale.
How often should response be exercised?
CSF does not fix a frequency; annual scenario exercises plus post-incident reviews is the pattern that survives scrutiny, with lessons demonstrably feeding improvement (ID.IM).
Your CSF 2.0 profile, built properly
Current and target profiles, gap analysis, and a prioritised roadmap that maps onto the ISO 27001, SOC 2 or SEBI CSCRF work you may already owe — kept current on SigmaTrust.
