Incident Response — FedRAMP KSI Domain
Generated from the official FedRAMP/rules GitHub repo. Source path:
fedramp-consolidated-rules.jsononmainat blob7d628b63fdd9. Consolidated Rules version:2026.07.02.02· upstreamlast_updated:2026-07-02. Supporting narrative documentation is available from the officialFedRAMP/2026-markdownrepository.
Incident Response
Domain code: INR · Domain ID: KSI-INR · Web slug: incident-response
Indicators
KSI-INR-AAR — Generating After Action Reports
Incident after action reports are generated and lessons learned are persistently incorporated.
Mapped Rev5 controls: ir-3, ir-4, ir-4.1, ir-8
Terms: Incident, Persistently
Recent update: 2026-06-24 — Official launch of the FedRAMP Consolidated Rules for 2026.
KSI-INR-RIR — Reviewing Incident Response Procedures
The effectiveness of documented incident response procedures is persistently reviewed.
Mapped Rev5 controls: ir-4, ir-4.1, ir-6, ir-6.1, ir-6.3, ir-7, ir-7.1, ir-8, ir-8.1, si-4.5
Terms: Incident, Persistently, Vulnerability Response
Recent update: 2026-06-24 — Official launch of the FedRAMP Consolidated Rules for 2026.
KSI-INR-RPI — Reviewing Past Incidents
Past incidents are persistently reviewed for patterns or vulnerabilities that were not previously apparent or identified.
Mapped Rev5 controls: ir-3, ir-4, ir-4.1, ir-5, ir-8
Terms: Incident, Persistently, Vulnerability
Recent update: 2026-06-24 — Official launch of the FedRAMP Consolidated Rules for 2026.