April 16, 2018 Function Category Communications (RC.CO): Restoration activities are coordinated with internal and external parties (e.g. coordinating centers, Internet Service Providers, owners of attacking systems, victims, other CSIRTs, and vendors). Cybersecurity Framework Subcategory Version 1.1 Informative References RC.CO-1: Public relations are managed COBIT 5 EDM03.02 ISO/IEC 27001:2013 A.6.1.4, Clause 7.4 RC.CO-2: Reputation is repaired after an incident COBIT 5 MEA03.02 ISO/IEC 27001:2013 Clause 7.4 RC.CO-3: Recovery activities are communicated to internal and external stakeholders as well as executive and management teams COBIT 5 APO12.06 ISO/IEC 27001:2013 Clause 7.4 NIST SP 800-53 Rev. 4 CP-2, IR-4 Information regarding Informative References described in Appendix A may be found at the following locations:    Control Objectives for Information and Related Technology (COBIT): http://www.isaca.org/COBIT/Pages/default.aspx CIS Critical Security Controls for Effective Cyber Defense (CIS Controls): https://www.cisecurity.org American National Standards Institute/International Society of Automation (ANSI/ISA)-62443-2-1 (99.02.01)-2009, Security for Industrial Automation and Control Systems: Establishing an Industrial Automation and Control Systems Security Program: https://www.isa.org/templates/one-column.aspx?pageid=111294&productId=116731  ANSI/ISA-62443-3-3 (99.03.03)-2013, Security for Industrial Automation and Control Systems: System Security Requirements and Security Levels: https://www.isa.org/templates/one-column.aspx?pageid=111294&productId=116785  ISO/IEC 27001, Information technology -- Security techniques -- Information security management systems -- Requirements: https://www.iso.org/standard/54534.html  NIST SP 800-53 Rev. 4 - NIST Special Publication 800-53 Revision 4, Security and Privacy Controls for Federal Information Systems and Organizations, April 2013 (including updates as of January 22, 2015). https://doi.org/10.6028/NIST.SP.800-53r4. Informative References are only mapped to the control level, though any control enhancement might be found useful in achieving a subcategory outcome. Mappings between the Framework Core Subcategories and the specified sections in the Informative References are not intended to definitively determine whether the specified sections in the Informative References provide the desired Subcategory outcome. Informative References are not exhaustive, in that not every element (e.g., control, requirement) of a given Informative Reference is mapped to Framework Core Subcategories. This publication is available free of charge from: https://doi.org/10.6028/NIST.CSWP.04162018 44

Select target paragraph3