FIRST CSIRT Services Framework and Standards
FIRST: Related Standards - CVSS, TLP, IEP, MPCVD and PSIRT Services

FIRST CSIRT Services Framework and Standards FIRST-Sectoral-NationalCSIRT: FIRST Sectoral Coordination - National CSIRTs, ISACs, ENISA, NIS2 + Industry Frameworks

FIRST coordination with national CSIRTs + sector ISACs + regional bodies + regulatory frameworks. NATIONAL CSIRTs (FIRST teams): US-CERT + CISA + DOE-CIRC + DOD-CYBERCOM + UK NCSC + AusCERT + JPCERT/CC + KrCERT/CC + CN-CERT + IR-CERT + many others (FIRST member directory at first.org/members lists 700+ teams). REGIONAL BODIES: (a) ENISA (EU Agency for Cybersecurity) - operates the CSIRTs Network under the NIS Directive + NIS2 + coordinates EU-level cyber crisis response + the CSIRT Network operates under TF-CSIRT (Task Force-CSIRT); (b) APCERT (Asia Pacific CERT) + OIC-CERT (Organization of Islamic Cooperation) + AfricaCERT + LACNIC-CERT; (c) AP-Cybersecurity + NA-Cybersecurity. SECTOR ISACs: Financial Services ISAC (FS-ISAC) + Health ISAC + Aviation ISAC (A-ISAC) + Auto-ISAC + Water-ISAC + Maritime-ISAC + Multi-State ISAC (MS-ISAC) + others - sector-specific threat sharing under FIRST coordination + standards. REGULATORY FRAMEWORKS: NIS2 (EU Directive 2022/2555) Article 14 CSIRTs Network coordination; CIRCIA (US Cyber Incident Reporting for Critical Infrastructure Act 2022) final rule 2026; FedRAMP M-24-15 modernization; EU CRA vulnerability handling. STANDARDS COORDINATION: NIST SP 800-61 Incident Response Lifecycle + ISO/IEC 27035 Information Security Incident Management + ITU-T X.1500 series + ENISA CSIRT Maturity (SIM3) baseline.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in FIRST: Related Standards - CVSS, TLP, IEP, MPCVD and PSIRT Services

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.