NIST 800-171 Controls · Incident Response
IR.2.093 — Track, document, and report incidents
Track, document, and report incidents to appropriate officials and/or authorities both internal and external to the organization.
What IR.2.093 means in plain English
When a security incident happens — even a minor one like a phishing email that someone clicked — you must write it down: what happened, when, who was affected, what you did about it, and what the outcome was. Some incidents must also be reported externally: if CUI is compromised or potentially compromised, you may need to report to the contracting officer and potentially DCSA within 72 hours. Keeping an "Incident Log" does not need to be fancy — even a shared Google Sheet or a SharePoint list works, as long as it is consistently maintained and backed up.
The assessment question
“Is every security incident (including minor events like phishing clicks) logged with date, description, impact assessment, response actions, and resolution — and are applicable incidents reported to required external authorities within required timeframes?”
How to implement IR.2.093
- Create an Incident Log template with fields: Incident ID, Date Detected, Date Reported, Incident Type, Systems Affected, Description of Event, Severity (Low/Medium/High/Critical), Containment Actions, Recovery Actions, Root Cause, Lessons Learned, and Reporter Name.
- Store the incident log in SharePoint or a secure shared drive with access limited to the IR Lead and senior management.
- Define reporting timelines in your IRP: internal notification within 1 hour of detection, external reporting to DOD contracting officer within 72 hours for any suspected CUI compromise (per DFARS 252.204-7012).
- Identify and record your specific reporting contacts: your Contracting Officer Representative (COR) name and email, DCSA CyberCrime notification address (dibnet.dod.mil), and your cyber insurance carrier.
- Train your team that "no incident is too small to log" — even suspected phishing or an employee clicking a suspicious link should generate a record.
Evidence your assessor will ask for
- Incident Log showing at least one real or simulated incident entry with all required fields
- External reporting contact list with current names, emails, and phone numbers
- Documented reporting timelines in the Incident Response Plan
- Evidence of at least one external report submitted (or attestation of no reportable incidents in the period)
- DFARS 252.204-7012 clause identified in at least one active contract
Does AI prompt monitoring help with this control? It supports it.
AI prompt monitoring does not satisfy IR.2.093 on its own, but its output feeds the capability this control requires: the tamper-evident event stream of allowed and blocked AI prompts becomes detection signal, incident record, and reviewable audit material. Treat the AI firewall as one input to this practice, alongside the remediation steps above.
Full mapping: which 800-171 controls AI prompt monitoring evidences →
More Incident Response controls
Score yourself against all 110 controls
The free ShieldReady assessment walks every NIST 800-171 requirement, computes your SPRS score, and shows exactly which gaps cost the most points.