We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

NIST CSF 2.0 · Function 5 of 6

Respond (RS): what it demands and how it is evidenced

Four categories covering the hours that decide breach outcomes: incident management, analysis, communication and mitigation. For Indian entities this function carries statutory weight — CERT-In’s 6-hour reporting window and sectoral timelines live inside RS.CO.

Reviewed by Tanya Kumari, Director — compliance assessment & certification readiness · Part of the CSF 2.0 series · CSF is voluntary guidance — we build profiles, not certificates

The categories inside Respond

RS.MA
Incident management

Response executed per plan once an incident is declared: triage, categorisation, prioritisation, escalation.

RS.AN
Incident analysis

Investigation to establish what happened and what is affected; evidence collected and preserved to support decisions and any legal process.

RS.CO
Incident response reporting and communication

Internal and external stakeholders informed per obligations — for India: CERT-In within 6 hours for notified incident types, plus RBI/SEBI/IRDAI and DPDP breach duties as applicable.

RS.MI
Incident mitigation

Incidents contained and eradicated — with the actions recorded as they happen, not reconstructed later.

Category identifiers reference NIST CSF 2.0 (26 February 2024) — nist.gov/cyberframework.

Where profiles fall short

Regulatory clocks discovered mid-incident

RS.CO fails when the 6-hour CERT-In window is looked up during the breach; the reporting matrix (who, what, when, how) must pre-exist and be drilled.

Evidence destroyed by the fix

Rebuilding a compromised host before imaging it satisfies RS.MI while destroying RS.AN — the runbook must sequence preservation before eradication where feasible.

Plans that have never met a scenario

Tabletops with lessons-learned records are the difference between a plan and a capability; every framework samples them.

Evidence that holds up

  • Incident response plan with declaration-to-closure workflow (RS.MA)
  • Forensic/evidence-handling procedure and sampled investigation records (RS.AN)
  • Regulatory reporting matrix (CERT-In 6h, sectoral, DPDP) with drill evidence (RS.CO)
  • Containment/eradication records from real incidents or exercises (RS.MI)
  • Tabletop records with lessons feeding ID.IM

Respond FAQ

What are the Indian reporting obligations inside RS.CO?

CERT-In requires notified incident types reported within 6 hours; sector regulators add their own windows (e.g. RBI frameworks with 2–6 hour expectations), and DPDP Rule 7 adds intimation to affected data principals without delay plus detailed reporting to the Board within 72 hours.

Does Respond include deciding NOT to act?

Yes — prioritisation under RS.MA includes risk-based decisions to monitor rather than immediately contain, documented with rationale.

How often should response be exercised?

CSF does not fix a frequency; annual scenario exercises plus post-incident reviews is the pattern that survives scrutiny, with lessons demonstrably feeding improvement (ID.IM).

Detect (DE)Recover (RC)

Your CSF 2.0 profile, built properly

Current and target profiles, gap analysis, and a prioritised roadmap that maps onto the ISO 27001, SOC 2 or SEBI CSCRF work you may already owe — kept current on SigmaTrust.