April 16, 2018
Function
Category
Communications (RC.CO):
Restoration activities are
coordinated with internal and
external parties (e.g. coordinating
centers, Internet Service
Providers, owners of attacking
systems, victims, other CSIRTs,
and vendors).
Cybersecurity Framework
Subcategory
Version 1.1
Informative References
RC.CO-1: Public relations are managed
COBIT 5 EDM03.02
ISO/IEC 27001:2013 A.6.1.4, Clause 7.4
RC.CO-2: Reputation is repaired after an
incident
COBIT 5 MEA03.02
ISO/IEC 27001:2013 Clause 7.4
RC.CO-3: Recovery activities are
communicated to internal and external
stakeholders as well as executive and
management teams
COBIT 5 APO12.06
ISO/IEC 27001:2013 Clause 7.4
NIST SP 800-53 Rev. 4 CP-2, IR-4
Information regarding Informative References described in Appendix A may be found at the following locations:
Control Objectives for Information and Related Technology (COBIT): http://www.isaca.org/COBIT/Pages/default.aspx
CIS Critical Security Controls for Effective Cyber Defense (CIS Controls): https://www.cisecurity.org
American National Standards Institute/International Society of Automation (ANSI/ISA)-62443-2-1 (99.02.01)-2009, Security
for Industrial Automation and Control Systems: Establishing an Industrial Automation and Control Systems Security Program:
https://www.isa.org/templates/one-column.aspx?pageid=111294&productId=116731
ANSI/ISA-62443-3-3 (99.03.03)-2013, Security for Industrial Automation and Control Systems: System Security Requirements
and Security Levels: https://www.isa.org/templates/one-column.aspx?pageid=111294&productId=116785
ISO/IEC 27001, Information technology -- Security techniques -- Information security management systems -- Requirements:
https://www.iso.org/standard/54534.html
NIST SP 800-53 Rev. 4 - NIST Special Publication 800-53 Revision 4, Security and Privacy Controls for Federal Information
Systems and Organizations, April 2013 (including updates as of January 22, 2015). https://doi.org/10.6028/NIST.SP.800-53r4.
Informative References are only mapped to the control level, though any control enhancement might be found useful in
achieving a subcategory outcome.
Mappings between the Framework Core Subcategories and the specified sections in the Informative References are not intended to
definitively determine whether the specified sections in the Informative References provide the desired Subcategory outcome.
Informative References are not exhaustive, in that not every element (e.g., control, requirement) of a given Informative Reference is
mapped to Framework Core Subcategories.
This publication is available free of charge from: https://doi.org/10.6028/NIST.CSWP.04162018
44