IEC-CSO-IIRInitial Incident Report
allvaries by class: a, b, c, d
The statement for this requirement varies by certification class — see the per-class deadlines below.
Who it binds
Controls whose FedRAMP guidance points at IEC (13)
Their guidance names the Incident Evaluation and Communication rules as a whole, not this requirement — so this is where to read from, not a mapping to this clause. Controls no KSI reaches have no page and are not listed.
Notifications (3)
- FedRAMPvia email: fedramp_security@fedramp.gov
- Agency Customersvia varies: varies by agency
- All Necessary Partiesvia update: trust center
Which certifications it binds
- Certification type
- 20x · Rev5
- Path
- Program · Agency
Machine-readable form
FedRAMP Incident Report (IEC-CSO-IIR / IEC-CSO-OIR / IEC-CSO-FIR)
https://fedramp.gov/schemas/fedramp-incident-report-schema-2026-06-24.json
Evidence this requirement demands
- An Initial Incident Report for one or more incidents. The report can be from real incidents, simulated incidents, or a combination of sources.class a
- An Initial Incident Report for one or more incidents. The report can be from real incidents, simulated incidents, or a combination of sources.class b
- An Initial Incident Report for one or more incidents. The report can be from real incidents, simulated incidents, or a combination of sources.class c
- An Initial Incident Report for one or more incidents. The report can be from real incidents, simulated incidents, or a combination of sources.class d
5 default artifacts owed by every FRR requirement
- Explanation of how the rule is followed, or an explanation of the reason and resulting risk to customers for not following the rule.
- Verification that the implementation is appropriate for the rule, or that the reason for not implementing is accepted by a senior official.
- Validation that the implementation is in place and working as intended, or that the reason for not implementing is accepted by a senior official.
- Independent verification.
- Independent validation.
Group all, subset CSO of Incident Evaluation and Communication. See all obligations on /obligations or the full evidence plan on /evidence.