NIST 800-53 r5 · Controls catalogue · Family IR
IR-3Incident Response Testing
Test the effectiveness of the incident response capability for the system {{ insert: param, ir-03_odp.01 }} using the following tests: {{ insert: param, ir-03_odp.02 }}.
Last updated: 09 May 2026 03:25 UTC
Implementations targeting this control (0)
- No implementations targeting this control yet.
ATT&CK techniques this control mitigates (0)
- No ATT&CK techniques mapped to this control yet.
Weaknesses this control addresses (7)AI
CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.
| CWE | Name | CVEs | Why this control addresses it |
|---|---|---|---|
CWE-754 | Improper Check for Unusual or Exceptional Conditions | 697 | IR testing directly validates checks for unusual or exceptional conditions that could indicate security incidents. |
CWE-755 | Improper Handling of Exceptional Conditions | 662 | Incident response testing confirms proper handling of exceptional conditions to limit exploit impact. |
CWE-703 | Improper Check or Handling of Exceptional Conditions | 146 | Performing IR tests ensures exceptional conditions are properly checked and handled to enable effective response. |
CWE-391 | Unchecked Error Condition | 23 | Testing IR effectiveness identifies and drives fixes for unchecked error conditions that fail to initiate incident handling. |
CWE-778 | Insufficient Logging | 23 | IR testing would reveal insufficient logging that impairs incident analysis and response effectiveness. |
CWE-390 | Detection of Error Condition Without Action | 14 | IR testing verifies that detected error conditions trigger appropriate response actions rather than being ignored. |
CWE-392 | Missing Report of Error Condition | 11 | IR testing would expose missing error reporting that prevents timely incident detection and response. |
Top CVEs where this control is the strongest mitigation
| CVE | Risk | CVSS | EPSS | Match |
|---|---|---|---|---|
| No CVEs annotated to this control yet — the per-CVE backfill is in progress. | ||||