1Overview
IR.L2-3.6.2 is the family's second five-point requirement and it governs the record and reach of incidents. It requires that the organization track, document, and report incidents to designated officials and authorities, both internal and external, so that incidents are recorded and the right people, inside and outside the organization, are told. It is a five-point requirement that cannot be deferred on a plan of action.
Handling an incident is not enough on its own; it has to be recorded and reported. Tracking and documenting incidents builds the history needed to learn from them and to demonstrate that response happened, and reporting ensures that the people who need to know, internal leadership and external authorities such as the government customer, are notified. For defense contractors, external reporting obligations can carry contractual and legal weight, so knowing who must be told and actually telling them is central. The five-point weight reflects that unreported incidents leave both the organization and its customer blind.
Track, document, and report incidents to designated officials and/or authorities both internal and external to the organization.
The requirement has three actions and two audiences. Tracking and documenting create the record of incidents; reporting delivers that information to designated recipients. The recipients fall into two groups: internal officials, such as organizational leadership, and external authorities, such as the government customer or relevant agencies. The organization has to identify who those recipients are in advance and actually notify them when an incident occurs, so that reporting is defined and executed rather than improvised in the moment.
2The Assessment Objectives
NIST SP 800-171A decomposes 3.6.2 into six objectives: track and document incidents, identify internal and external recipients, and notify each.
Incidents are tracked. The organization maintains a record of incidents.
Incidents are documented. Each incident is recorded with its details.
Authorities to whom incidents are to be reported are identified. The external recipients are known in advance.
Organizational officials to whom incidents are to be reported are identified. The internal recipients are known in advance.
Identified authorities are notified of incidents. External recipients are actually told.
Identified organizational officials are notified of incidents. Internal recipients are actually told.
The six objectives cover tracking, documenting, identifying both audiences, and notifying each. The common gap is at objectives [c] and [e], the external side, where the organization has not identified who to report to externally or does not actually report, which for defense contractors can carry contractual consequences. The assessor looks for tracking, documentation, and reporting that reaches both audiences.
3Failure Patterns
The failures are about incidents that go unrecorded or unreported, especially externally.
No external reporting path
Where the organization has not identified who to report incidents to externally, or does not report when required, it fails the external objectives and may breach a contractual obligation. Identifying the external authorities and reporting to them is essential.
Incidents handled but not documented
An incident resolved informally with no record leaves nothing to learn from or to demonstrate, failing the documentation objective. Documenting each incident builds the history the organization needs.
Leadership left uninformed
Where internal officials are not notified, decision-makers are blind to incidents affecting the organization. Internal reporting has to reach the identified officials.
Recipients not identified in advance
Without identifying internal and external recipients ahead of time, reporting is improvised under pressure and may miss required parties. The recipients have to be identified before an incident, not decided during one.
4Ownership
This is a security-owned control with a reporting dimension that often involves leadership and, for external obligations, counsel.
| Role | Responsibility for this control |
|---|---|
| Security or compliance lead | Tracks and documents incidents, identifies internal and external recipients, and ensures reporting occurs. Owns the incident records. |
| Leadership | Receives internal incident reports and supports meeting external obligations. |
| Counsel | Advises on external reporting obligations, which for defense contractors can carry contractual and legal weight. |
5Tooling
The control is delivered by incident tracking and documentation and by defined reporting to identified recipients.
| Objectives | Tooling | What it provides |
|---|---|---|
| [a], [b] | Incident log or ticketing system | Tracking and documentation of incidents. |
| [c], [d] | Defined reporting recipients, internal and external | Identification of who must be notified. |
| [e], [f] | Reporting procedures and records | Actual notification of the identified recipients. |
The caveat is that identifying recipients is not the same as notifying them, and the external obligation is the one most often missed. Reporting has to actually reach both the internal officials and the external authorities, with records to show it. The assessor examines tracking, documentation, and reporting to both audiences, so the external path in particular has to be real.
6Evidence
The satisfied version of 3.6.2 shows tracked, documented incidents reported to both audiences.
| Evidence | What it demonstrates |
|---|---|
| Incident log or records | Objectives [a], [b]. Incidents tracked and documented. |
| Identified recipients | Objectives [c], [d]. Internal officials and external authorities identified. |
| Reporting records | Objectives [e], [f]. Notification of the identified recipients. |
The evidence should show incidents tracked and documented, with reporting reaching both identified internal officials and external authorities. The incident records together with identified recipients and reporting records are the clearest demonstration, and because this control cannot sit on a plan of action, the tracking and reporting have to be real at the time of assessment.
An unreported incident leaves everyone blind
Handling an incident is not enough if it is never recorded or the right people, inside and outside, are never told, and for a defense contractor the external obligation can carry real consequences. Building incident tracking and a reporting path that reaches both audiences is part of the onsite readiness work this practice does, and it is one of the controls that must be met rather than deferred.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.6.2. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.6.2[a] through 3.6.2[f]. csrc.nist.gov
- 32 CFR 170.24, CMMC Scoring Methodology, listing IR.L2-3.6.2 among the five-point basic security requirements. ecfr.gov