FIRST CSIRT Services Framework and Standards
FIRST: Related Standards - CVSS, TLP, IEP, MPCVD and PSIRT Services

FIRST CSIRT Services Framework and Standards FIRST-Status-Pipeline: FIRST Standards Pipeline - 2024-2025 Roadmap and Coordination with NIS2, CIRCIA, EU CRA

FIRST standards pipeline + 2024-2025 roadmap. CURRENT STANDARDS: CSIRT Services Framework v2.1 (2019) + CVSS v4.0 (2023) + TLP v2.0 (2022) + IEP v2.0 + MPCVD Guidelines + PSIRT Services Framework v1.1 (2020). UPCOMING + IN DEVELOPMENT: (a) CSIRT Services Framework v3 (anticipated 2026-2027) with refinements for cloud + supply chain + AI-related incident handling; (b) CVSS v4.x interim revisions for emerging-threat metrics; (c) IEP v2.x machine-readable enhancements; (d) SECURITY OPERATIONS SERVICES FRAMEWORK (SOSF) for SOC-style operations; (e) AI INCIDENT RESPONSE GUIDELINES for AI-system incidents + AI Safety Institutes coordination. REGULATORY ALIGNMENT: NIS2 (in force October 2024) + Cybersecurity Act 2024 transpositions in EU Member States; CIRCIA Final Rule effective 2026 for US critical infrastructure (60+ hour notification window); EU CRA (Regulation (EU) 2024/2847) vulnerability handling obligations 2026-2027; the 2024 OMB M-22-09 + 2024 ZTA strategy + FedRAMP M-24-15 modernization. 2024-2025 PRIORITIES: ransomware response + supply chain incidents + nation-state activity + AI-system security incidents + cross-border coordination + automated CTI exchange.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in FIRST: Related Standards - CVSS, TLP, IEP, MPCVD and PSIRT Services

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.