NIST SP 800-61 Rev. 3
Respond (RS): incident response – NIST SP 800-61 Rev. 3

NIST SP 800-61 Rev. 3 RS.AN-03: RS.AN-03 Sequence of events, actors and root causes of the incident established

CSF 2.0 outcome: analysis is performed to establish what has taken place during an incident and the root cause of the incident. Priority High. R1: determine the sequence of events during the incident and the assets and resources involved in each. R2: try to determine the vulnerabilities, threats and threat actors directly or indirectly involved. R3: analyze the incident for underlying or systemic root causes. R4: check any deployed cyber deception technology for more information on attacker behaviour. N1: this can also show risk management weaknesses to fix so that similar incidents do not recur.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-RS.AN-03 Analysis is performed to establish what has taken place during an incident and the root cause of the incident

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Respond (RS): incident response – NIST SP 800-61 Rev. 3

Query this from an agent

The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.