NIST SP 800-171 & CMMC 2.0 - 3.6.1

Establish an operational incident-handling capability for organizational systems that includes preparation, detection, analysis, containment, recovery, and user response activities.

NIST SP 800-171 & CMMC 2.0 - 3.6.2

Track, document, and report incidents to designated officials and/or authorities both internal and external to the organization.

NIST SP 800-171 & CMMC 2.0 - 3.6.3

Test the organizational incident response capability.