<?xml version="1.0" encoding="UTF-8"?><!--Serialized by the GTRI Trustmark Framework API, version: 1.4.74--><tf:TrustInteroperabilityProfile xmlns:tf="https://trustmarkinitiative.org/specifications/trustmark-framework/1.4/schema/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:ds="http://www.w3.org/2000/09/xmldsig#"><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tips/nist-sp-800-53-r4-security-control-ir-8_-incident-response-plan/4/</tf:Identifier><tf:Name>NIST SP 800-53 r4 Security Control IR-8: Incident Response Plan</tf:Name><tf:Version>4</tf:Version><tf:Description>Profile of requirements corresponding to NIST Special Publication 800-53, r4, Security Control IR-8: Incident Response Plan. Applicable to LOW impact, MODERATE impact, and HIGH impact systems.</tf:Description><tf:PublicationDateTime>2021-04-26T00:00:00.000Z</tf:PublicationDateTime><tf:Primary>false</tf:Primary><tf:LegalNotice>This document and the information contained herein is provided on an "AS IS" basis, and the Georgia Tech Research Institute disclaims all warranties, express or implied, including but not limited to any warranty that the use of the information herein will not infringe any rights or any implied warranties or merchantability or fitness for a particular purpose. In addition, the Georgia Tech Research Institute disclaims legal liability for any loss incurred as a result of the use or reliance on the document or the information contained herein.</tf:LegalNotice><tf:Issuer><tf:Identifier>https://trustmarkinitiative.org/</tf:Identifier><tf:Name>TMI</tf:Name><tf:Contact><tf:Kind>PRIMARY</tf:Kind><tf:Responder></tf:Responder><tf:Email>help@trustmarkinitiative.org</tf:Email><tf:Telephone>555-555-5555</tf:Telephone><tf:WebsiteURL>https://trustmarkinitiative.org/</tf:WebsiteURL></tf:Contact></tf:Issuer><tf:Keywords><tf:Keyword>800-53</tf:Keyword><tf:Keyword>High</tf:Keyword><tf:Keyword>Incident Response</tf:Keyword><tf:Keyword>Incident Response Plan</tf:Keyword><tf:Keyword>Low</tf:Keyword><tf:Keyword>Moderate</tf:Keyword><tf:Keyword>NIST</tf:Keyword><tf:Keyword>P1</tf:Keyword><tf:Keyword>Security</tf:Keyword></tf:Keywords><tf:References><tf:TrustmarkDefinitionRequirement tf:id="TD_ref1"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/incident-response-plan-roadmap/1.0/</tf:Identifier><tf:Number>1</tf:Number><tf:Name>Incident Response Plan Roadmap</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Defines conformance and assessment criteria for compliance with minimum security requirements for incident response plan roadmap as related to overall incident response requirements.</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_ref2"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/incident-response-plan-review-and-approval/1.0/</tf:Identifier><tf:Number>2</tf:Number><tf:Name>Incident Response Plan Review and Approval</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Defines conformance and assessment criteria for compliance with minimum security requirements for incident response plan review and approval as related to overall incident response requirements.</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_ref3"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/incident-response-plan-approach/1.0/</tf:Identifier><tf:Number>3</tf:Number><tf:Name>Incident Response Plan Approach</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Defines conformance and assessment criteria for compliance with minimum security requirements for incident response plan approach as related to overall incident response requirements.</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_ref4"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/incident-response-plan-metrics/1.0/</tf:Identifier><tf:Number>4</tf:Number><tf:Name>Incident Response Plan Metrics</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Defines conformance and assessment criteria for compliance with minimum security requirements for incident response plan metrics as related to overall incident response requirements.</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_ref5"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/incident-response-plan-structure/1.0/</tf:Identifier><tf:Number>5</tf:Number><tf:Name>Incident Response Plan Structure</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Defines conformance and assessment criteria for compliance with minimum security requirements for incident response plan structure as related to overall incident response requirements.</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_ref6"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/incident-response-plan-communication-of-changes/1.0/</tf:Identifier><tf:Number>6</tf:Number><tf:Name>Incident Response Plan Communication of Changes</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Defines conformance and assessment criteria for compliance with minimum security requirements for incident response plan communication of changes as related to overall incident response requirements.</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_ref7"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/incident-response-plan-protection/1.0/</tf:Identifier><tf:Number>7</tf:Number><tf:Name>Incident Response Plan Protection</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Defines conformance and assessment criteria for compliance with minimum security requirements for incident response plan protection as related to overall incident response requirements.</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_ref8"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/incident-response-plan-organizational-requirements/1.0/</tf:Identifier><tf:Number>8</tf:Number><tf:Name>Incident Response Plan Organizational Requirements</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Defines conformance and assessment criteria for compliance with minimum security requirements for incident response plan organizational requirements as related to overall incident response requirements.</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_ref9"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/incident-response-plan-resources/1.0/</tf:Identifier><tf:Number>9</tf:Number><tf:Name>Incident Response Plan Resources</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Defines conformance and assessment criteria for compliance with minimum security requirements for incident response plan resources as related to overall incident response requirements.</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_ref10"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/periodic-review-of-incident-response-plan/1.0/</tf:Identifier><tf:Number>10</tf:Number><tf:Name>Periodic Review of Incident Response Plan</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Defines conformance and assessment criteria for compliance with minimum security requirements for periodic review of incident response plan as related to overall incident response requirements.</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_ref11"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/incident-response-plan-defines-reportable-incidents/1.0/</tf:Identifier><tf:Number>11</tf:Number><tf:Name>Incident Response Plan Defines Reportable Incidents</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Defines conformance and assessment criteria for compliance with minimum security requirements for incident response plan Defines reportable incidents as related to overall incident response requirements.</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_ref12"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/incident-response-plan-updates/1.0/</tf:Identifier><tf:Number>12</tf:Number><tf:Name>Incident Response Plan Updates</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Defines conformance and assessment criteria for compliance with minimum security requirements for incident response plan updates as related to overall incident response requirements.</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_ref13"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/incident-response-plan-distribution/1.0/</tf:Identifier><tf:Number>13</tf:Number><tf:Name>Incident Response Plan Distribution</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Defines conformance and assessment criteria for compliance with minimum security requirements for incident response plan distribution as related to overall incident response requirements.</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement></tf:References><tf:TrustExpression><![CDATA[TD_ref1 and TD_ref2 and TD_ref3 and TD_ref4 and TD_ref5 and TD_ref6 and TD_ref7 and TD_ref8 and TD_ref9 and TD_ref10 and TD_ref11 and TD_ref12 and TD_ref13]]></tf:TrustExpression><tf:Sources><tf:Source tf:id="Source-2112165102"><tf:Identifier>SP800-53R4</tf:Identifier><tf:Reference>NIST Special Publication 800-53 Revision 4, Security and Privacy Controls for Federal Information Systems and Organizations, National Institute of Standards and Technology, April 2013 (Includes updates as of 01-15-2014). Available at &lt;a href="http://dx.doi.org/10.6028/NIST.SP.800-53r4"&gt;http://dx.doi.org/10.6028/NIST.SP.800-53r4&lt;/a&gt;.</tf:Reference></tf:Source></tf:Sources></tf:TrustInteroperabilityProfile>