Annex I · Objective 05
Answer
Reply coordinates actions executed during or after an incident to limit damage and maintain control.
Complete structure
Categories and controls.
Select each category to see all the codes and titles that make up it.
RS.GIIncident Management5 checks
- RS.GI-1
The Incident Response Plan is implemented in coordination with stakeholders.
- RS.GI-2
Notifications of detection systems shall be screened and validated.
- RS.GI-3
Incidents are categorized according to the Incident Response Plan.
- RS.GI-4
The incidents are scaled or elevated as necessary.
- RS.GI-5
The criteria for initiating incident recovery are applied.
RS.AIIncident Analysis4 checks
- RS.AI-1
Forensic analysis is performed to determine what happened and the root cause.
- RS.AI-2
The research actions are recorded and the integrity and provenance of the records are preserved.
- RS.AI-3
The incident data and metadata are collected with preserved integrity and provenance.
- RS.AI-4
The impact of the incident is estimated and validated.
RS.NCNotification and Communication of Incidents2 checks
- RS.NC-1
Internal and external stakeholders are notified of the incidents.
- RS.NC-2
There is voluntary sharing of information with external stakeholders.
RS.MIMitigation2 checks
- RS.MI-1
The incidents are contained.
- RS.MI-2
The incidents are solved.
Application
How to work every control.
- Confirm full description in Annex I
- Set scope and responsibility
- Relating control with risk and critical services
- Associate implementation and evidence
- Record gaps, priority and deadline
- Review implementation and effectiveness
Primary source
Regulation No. 756/2026, of 22 June — Annex I
The codes and titles reproduce the structure of Annex I. Please refer to the official act for the full description and normative references of each control.