NIST SP 800-123
IR and Decommissioning

NIST SP 800-123 NISTSP123-7: Incident Response and Server Decommissioning

Implement Section 7.1 incident response for servers per NIST SP 800-61 covering preparation + detection + analysis + containment + eradication + recovery + post-incident review + coordination with CSIRT + US-CERT + CISA + Cyber Threat Intelligence (CTI) sharing per STIX/TAXII. Apply Section 7.2 server decommissioning including: data sanitisation per NIST SP 800-88 (clear + purge + destroy based on confidentiality categorisation) + media handling + secure disposal + asset removal from inventory + license recovery + DR plan updates + documentation. Maintain chain of custody for evidence and asset disposal.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.