NIST CSF RS.CO - Incident Response Reporting and Communication
Coordinate incident response communication with internal and external stakeholders including notifications, information sharing with designated parties, and reporting to authorities and ISACs as required by law
Where this comes from
Provision: RS.CO - Incident Response Reporting and Communication
Instrument: NIST Cybersecurity Framework 2.0 (February 2024)
Citation: NIST Cybersecurity Framework 2.0, February 26, 2024, Section RS.CO (Incident Response Reporting and Communication), Sub-categories RS.CO-01 through RS.CO-03
Text version: CSF 2.0
Who it applies to
It applies when all of these are true:
- Data categories collected — any answer
- Service is likely to be accessed by children under 18
What engineering work it implies
Sample acceptance criteria Landfall generates for this obligation:
- Information is clearly displayed to users
- Disclosure is accessible and understandable
- Disclosure timing is appropriate (before action)
- Language is appropriate for the audience
- Test: the disclosure is visible before the user acts on it
Questions people ask
- Does NIST CSF RS.CO - Incident Response Reporting and Communication apply to my service?
- It applies when Data categories collected — any answer; Service is likely to be accessed by children under 18.
- From when does this apply?
- NIST CSF RS.CO - Incident Response Reporting and Communication applies from 26 February 2024. Its current status is: in force.
Find out whether this one lands on you
Landfall's pre-scan answers the applicability question above for your product in minutes, then turns every obligation that applies into traceable engineering tickets with a citation chain your auditors can follow.
Not legal advice. Landfall maps regulatory obligations to engineering work for planning purposes. Its verdicts are not legal advice and create no attorney-client relationship — verify with qualified counsel before relying on them.