NIST SP 800-61 Rev. 3
Identify (ID): preparation and lessons learned – NIST SP 800-61 Rev. 3

NIST SP 800-61 Rev. 3 ID.RA-02: ID.RA-02 Cyber threat intelligence received and used for incident response

CSF 2.0 outcome: cyber threat intelligence is received from information sharing forums and sources. Priority High. N1: CTI is threat information aggregated, transformed, analyzed, interpreted or enriched to give the context decisions need, received from automated feeds, sharing forums and other sources. N2: CTI helps response and recovery by informing on new threats, improving the accuracy of detection and response technologies and describing attackers' tactics, techniques and procedures (TTPs), which are widely documented in repositories and knowledge bases. N3: SP 800-150 covers consuming, using and storing CTI and establishing sharing relationships. N4: see the ID.RA notes.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-ID.RA-02 Cyber threat intelligence is received from information sharing forums and sources

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Identify (ID): preparation and lessons learned – NIST SP 800-61 Rev. 3

Query this from an agent

The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.