Control Statement
Incident and recovery information shall be shared with designated internal stakeholders, external partners and the public as the situation and the agency's obligations require, within stated periods.
Purpose. To ensure the people who must know, do — inside the agency, across the federal community, and among those the mission serves.
Discussion
This control covers three audiences with different clocks and is distinct from CE-7, which distributes the cycle Brief internally on a cadence. Internal stakeholder notification is an operational obligation; federal reporting to CISA and sector partners is frequently a statutory one with a defined window; and public communication during a recovery is where a federal agency's obligation to the people it serves becomes concrete. The framework's own material puts the community reporting case well: reporting is not altruism in a federal community — it is how the next agency's spoiling attack becomes possible, and how yours does.
Goals and Metrics
A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.
- Percentage of required communications delivered within their stated window
- Count of missed-window findings per cycle
- Proportion of eradicated incidents resulting in a community contribution
- Number of contributions made to federal or sector partners per cycle
Accountability
Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.
| AO | CTI | SOC | HUNT | PLAT | ISSO |
|---|---|---|---|---|---|
| Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Consulted | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Informed | Governance / RMF / ISSO: Responsible |
AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO
- AccountableAuthorizing Official / CISO
- ConsultedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- InformedPlatform and product owners
- ResponsibleGovernance / RMF / ISSO
Inputs and Outputs
Consumes
- EN-1 Event Declaration and TriageDeclared incidents and their category
- EN-2 Engagement ReconstructionReconstruction and magnitude, which set what must be reported
- EN-5 Eradication and Transition to RecoveryEradication status
- FO-7 Obligation Profile DeclarationObligation profile determining which statutory windows bind
Produces
- CG-4 Findings DispositionMissed-window findings requiring disposition
- CE-6 Cycle Record and TrendCommunication record forming part of the cycle history
Activities
- L2Identify the internal stakeholders, external partners and public audiences to be informed.
- L2Communicate incident information to each within stated periods.
- L2Communicate recovery status and completion as the situation develops.
- L3Record the statutory or policy reporting windows applying to each recipient, with provenance per
GA4, and treat a missed window as a finding. - L3Define what may be shared with each audience at each stage, so operational sensitivity and the duty to inform are reconciled in advance rather than negotiated during.
- L3Share indicators and tradecraft with sector partners and CISA once eradication permits, consistent with
M10.05and the agency's disclosure authorities. - L3Designate the communication authority per audience, since public communication is a command decision rather than an analyst's.
- L3Provide recovery status to those affected by the mission impact, not only to internal stakeholders.
- L4Measure communication timeliness against each stated window and trend it.
- L4Measure the proportion of eradicated incidents that resulted in a community contribution, since a program that only receives from the community is not participating in it.
- L5Review communications after each engagement against what recipients actually needed, and revise the audience and content definitions.
Measurement
Percentage of required communications delivered within their stated window.
Proportion of eradicated incidents resulting in a community contribution.
Evidence and Assessment
Communication records with recipients, content, authority and timing; reporting window register; community contribution records; missed-window findings.
Examine communications against stated windows; test that the designated authority approved public communication; examine whether recent engagements produced community contributions.
Related Guidance
- IR-6
- IR-9
- PM-16
- RS.CO-02
- RS.CO-03
- RC.CO-03
- RC.CO-04
Position in the Chain
Derived from the other controls’ own declarations, so the two directions cannot disagree.
Feeds
Nothing downstream — this control terminates a chain.
Where This Control Is Used
Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.
Forms of Maneuver It Assesses
- M9Spoiling AttackDisrupt adversary staging before the attack is launched.1 of 9 techniques — M9.04
- M10Exploitation & PursuitConvert contact into durable advantage rather than closing the ticket.1 of 7 techniques — M10.05
Terrain It Is Named On
Applies to all ten layersReports what happened on this layer to those who must know, inside and outside the agency.
Artifacts It Stands On
- producesEngagement communication recordWho was told what, and when, against the window that bound each obligation — inside the agency, to the federal community, and to those the mission serves. Includes the contribution made back to the community, or the recorded reason there was none.
- consumesEngagement recordThe record of one engagement end to end: what was declared and on what criteria, the reconstruction with its dwell, scope and confidence, the evidence preserved and its custody, the authority exercised, and the verification that eradication actually happened before recovery began.
Roles It Puts to Work
- AccountableAuthorizing Official / CISOIntent, risk acceptance, and the scheme itself.
- ResponsibleGovernance / RMF / ISSOTranslating cycle outputs into FISMA and RMF artifacts, and owning the rules of engagement.
- ConsultedCyber Threat Intelligence cellFrame, Map and Fuse. The intelligence requirements, the threat courses of action, and the confidence levels.
- ConsultedSOC / Defensive OperationsManeuver. Executes fires and emplaces obstacles inside the standing rules of engagement.
- InformedHunt teamCounterattack. Works the hypotheses that Fuse raises.
- InformedPlatform and product ownersTheir own terrain. Obstacles get emplaced on their ground, so they site them.