RS.MA-01 RS · Respond · RS.MA Incident Management

RS.MA-01 — Response plan execution

The incident response plan is executed in coordination with relevant third parties once an incident is declared.

Also written as RS-MA-01, RS.MA-1, CSF 2.0 RS.MA-01, NIST CSF RS.MA.

What NIST CSF RS.MA-01 means

RS.MA-01 is one of 13 subcategories in the Respond (RS) function, under the Incident Management category (RS.MA). The Core states: “The incident response plan is executed in coordination with relevant third parties once an incident is declared.” Respond outcomes are hard to evidence without incidents, so exercises and tabletop records carry the weight: they are what shows the capability exists before it is needed.

Evidence that supports RS.MA-01

To demonstrate this outcome in an assessment or audit, gather artefacts such as:

  • Incident response plan invocation records
  • Coordination evidence with third parties during incidents
  • IR plan alignment with declared incident records

ISO 27001 mapping

RS.MA-01 corresponds to the following ISO 27001:2022 Annex A control(s): A.5.24, A.5.26. Evidence collected for one framework typically supports the other.

Map RS.MA-01 to ISO 27001 & SOC 2 →
Crosswalk this subcategory in the Control Mapper & Gap Assessment.
Document the risk →
Record treatment for gaps against RS.MA-01 in the Risk Register.

Other Incident Management subcategories

RS.MA-02 Incident report triage and validation RS.MA-03 Incident categorization and prioritization RS.MA-04 Incident escalation RS.MA-05 Recovery initiation criteria

All 13 Respond subcategories →

Frequently asked questions

Is NIST CSF RS.MA-01 mandatory?

No. CSF 2.0 is a voluntary framework of outcomes rather than a set of requirements, and there is no certification against it. RS.MA-01 becomes binding only when something else makes it so — a contract, a regulator that references CSF, or your own Target Profile. That is the practical difference between CSF and an auditable standard like ISO 27001 or SOC 2.

How is RS.MA-01 assessed?

Through profiles rather than pass/fail testing. You record how fully the outcome is achieved today in a Current Profile, state where it needs to be in a Target Profile, and the gap between them becomes your action plan. Implementation Tiers (Partial, Risk Informed, Repeatable, Adaptive) describe how rigorous your governance around the outcome is, not whether you have met it.

Who owns RS.MA-01?

The Respond function is normally owned by the security or IT function, but RS.MA-01 still needs a specific named owner. Assessors treat an outcome with no owner as not achieved regardless of the tooling behind it, so record ownership in your profile alongside the assessment.

Does NIST CSF RS.MA-01 map to ISO 27001?

Yes — RS.MA-01 corresponds to ISO 27001:2022 Annex A control(s) A.5.24, A.5.26. Evidence collected for one framework typically supports the other, so a single control library can serve both.