NIST SP 800-61 Rev. 3
Govern (GV): preparation – NIST SP 800-61 Rev. 3

NIST SP 800-61 Rev. 3 GV.PO: GV.PO Cybersecurity policies include an incident response policy

CSF 2.0 Category: organizational cybersecurity policy is established, communicated and enforced. Priority High. R1: cybersecurity policies should include an incident response policy. Section 2.3: organizations should have policies governing incident response, which typically contain a statement of management commitment, purpose and objectives, scope (to whom and what it applies and when), definitions of events, incidents, investigations and related terms, roles, responsibilities and authorities (such as who may confiscate, disconnect or shut down assets), guidelines for prioritizing incidents, estimating severity, initiating recovery and maintaining or restoring operations, and performance measures. Processes and procedures should follow the policy and plan; documented procedures should cover the most common incident and threat types and urgent processes such as redeploying the primary authentication platform, can be tested or exercised and used in training, and are often written as playbooks. The recommendation applies to GV.PO-01 and GV.PO-02.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in Govern (GV): preparation – NIST SP 800-61 Rev. 3

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.