NIST CSF 2.0 · derived mapping target
RS.AN-03Incident analysis performed
Analyze what took place during an incident and find the root cause, so you fix the real problem and not just the symptoms.
Mapping at a glance
RS.AN-03Incident analysis performedNIST CSF 2.0
RS.AN-03 is covered by 3 Sekit CSF controls. Open in the full graph →
Mapped from the Sekit CSF
The Sekit controls that cover this requirement, lens by lens.
RCF-0268Forensics readiness · PolicyRCF-0269Forensics readiness · ProcessRCF-0270Forensics readiness · Technical
ISO/IEC 27001:2022 counterparts
Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
Incident playbooks, exercises and forensics readiness
The step-by-step guides for the most likely incidents, the tabletop exercises, the post-incident review reports, and how evidence is preserved so an incident can be investigated.
From the Sekit evidence catalog
Ask Sekura: “What evidence proves RS.AN-03?”
Also via MCP, free with account