CMMCpedia Download

Requirements / Incident Response (IR)

IR.L2-3.6.2

Incident Reporting

Official Source Material

Track, document, and report incidents to designated officials and/or authorities both internal and external to the organization.

Determine if:

  1. [a] incidents are tracked;
  2. [b] incidents are documented;
  3. [c] authorities to whom incidents are to be reported are identified;
  4. [d] organizational officials to whom incidents are to be reported are identified;
  5. [e] identified authorities are notified of incidents; and
  6. [f] identified organizational officials are notified of incidents.

Source: CMMC Assessment Guide - Level 2, Version 2.13, September 2024

Practitioner Guidance

How to meet it

The six objectives are three pairs: record, identify, notify.

Objectives [a] and [b] ask for a record of incidents. Objectives [c] and [d] ask you to name the external authorities and internal officials who get told. Objectives [e] and [f] ask for evidence that the identified parties actually hear about incidents when they occur. Build the requirement in that order.

Tracking is a log. Documentation is the story of each incident.

A ticket system or a spreadsheet with an entry per incident, its status, and its dates satisfies [a] at any size. Documentation under [b] is the fuller record: what was observed, which systems were involved, what was done, and when it closed. Keep both, because the log across time is how you spot a repeat problem.

Define what you report externally before an incident forces the question.

Write a reportable incident definition into your plan: which events require notification outside the organization and which stay internal. Anchor the external threshold to DFARS 252.204-7012, the safeguarding clause in your DoD contracts. It covers a cyber incident that affects a covered contractor information system, the covered defense information on it, or your ability to provide operationally critical support. Reports go to DoD within 72 hours of discovery. A definition on paper turns a 2 a.m. judgement call into a lookup.

Not every malware detection is a reportable cyber incident.

Malware that your endpoint protection blocked and quarantined before it touched CUI, the Controlled Unclassified Information you protect, did not adversely affect the system. Record the detection, judge it against your written definition, and keep the determination with the ticket. The record of a considered decision is [a] and [b] working as intended.

Name the authorities and the officials now, and secure the access to reach them.

For DoD work the external report goes through DIBNET, DoD's incident reporting portal at dibnet.dod.mil. Submitting one requires a DoD-approved medium assurance certificate, a purchased identity credential that takes longer to obtain than the 72 hours you would have. Get the certificate before you need it. Internally, name the roles that hear about an incident: the owner, the program lead, whoever calls the prime contractor above you. Put names against the roles in the plan. That covers [c] and [d].

A clean history is documented, not assumed.

When no incident has met your reporting threshold, keep the tracking log anyway. Record a dated statement that no incidents have required external notification since your system security plan, the document that says how each requirement is met, took effect. Keep the thresholds themselves alongside it. Objectives [e] and [f] are then evidenced by the working procedure and the empty log, and an assessor can follow the path a real incident would take.

What falls short

  • A policy that says incidents will be reported to the appropriate authorities without naming them. Objectives [c] and [d] ask for identified authorities and officials, and appropriate is not a name.
  • An incident that was handled well but never written down. A verbal account leaves nothing for [b].
  • Waiting for an incident to sort out DIBNET access. A report due within 72 hours cannot wait on a certificate application, so the notification duty behind [e] goes unmet when it matters.

Edge cases

  • Subcontractors report their own cyber incidents to DoD under DFARS 252.204-7012 and pass the incident report number to the prime. Check the contract for additional notification duties the prime added, and write both paths into the plan.
  • Suspicious email that looks like targeted phishing belongs in the tracking log even when nothing was compromised. Let the written threshold decide whether anyone outside the organization needs to hear about it.

CMMCpedia is independently maintained and is not affiliated with the U.S. Department of Defense. The content is educational. It is not legal advice, and it does not guarantee certification.