RS.MI — Incident Mitigation
Activities are performed to prevent expansion of an event and mitigate its effects
RS.MI-01
Incidents are contained
RS.MI-02
Incidents are eradicated
Source: NIST Cybersecurity Framework 2.0 · CSF 2.0 → 800-53 mappings sourced from NIST Cybersecurity & Privacy Reference Tool (CPRT) · US government work — attribution requested per NIST Open License Terms. Direct CSF→CWE/CVE cross-references will be added in a Phase B LLM-authored mapping pass (not yet rendered).