Controls / MCSB / IR-4

MCSB IR-4: Incident Response

3 Senserva Microsoft 365 security checks provide evidence for Microsoft Cloud Security Benchmark control IR-4 (Incident Response). Each is checked against your tenant, ranked by Severity, with validated remediation.

3 checksIncident ResponseTop Severity: Critical

What MCSB IR-4 covers

The Microsoft Cloud Security Benchmark is Microsoft's own security baseline for Azure and Microsoft 365, organized into control domains. IR-4 sits in the Incident Response domain. Senserva evidences it with the 3 checks below, so you can see, per tenant, whether the control is actually met rather than assumed.

Ask your own AI about this control

Copy this prompt into Claude, ChatGPT, or Copilot. The facts are included, sourced from this page.

The 3 checks that evidence MCSB IR-4

Click any row for why it matters and how to fix it, with a link to the full check page.

Senserva checkSeverityWhat it verifies
Risk Detection OfflineCriticalRisk detection was discovered offline (retroactively). The compromise predates the detection
Risk Detection StaleHighUnresolved risk detection has exceeded the configured stale threshold
Ir Update Incident Response Plan And ProcessMediumUpdate and maintain the incident response plan and process

Also evidences

The same checks provide evidence for these frameworks, so one fix counts across your obligations:

Every MCSB control and the checks that evidence it: the control reference. The full benchmark crosswalk: MCSB for Microsoft 365.

Reference: the compliance frameworks crosswalk, the check reference, and the audit guide.
Data notice: control mappings describe which Siemserva checks provide evidence for a control and are informational only, without warranty. They do not constitute compliance advice or certification; confirm requirements with your assessor. All use is subject to the Senserva EULA.