NIST SP 800-61 Rev. 3
Respond (RS): incident response – NIST SP 800-61 Rev. 3

NIST SP 800-61 Rev. 3 RS.AN-07: RS.AN-07 Incident data collected and retained as evidence under preservation procedures

CSF 2.0 outcome: incident data and metadata are collected, and their integrity and provenance are preserved. Priority High. N1: most responses collect incident data and metadata; formal chain of custody may not be used for every incident (most malware incidents will not be prosecuted), but collected data is still evidence, defined in SP 800-160v1 as grounds for belief or disbelief, data on which to base proof or to establish truth or falsehood. R1: collect and retain incident evidence under the organization's evidence preservation procedures and data retention policies, weighing the possibility of prosecution and the cost of retaining the data and the hardware and software needed to read it later.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-RS.AN-07 Incident data and metadata are collected, and their integrity and provenance are preserved

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Respond (RS): incident response – NIST SP 800-61 Rev. 3

Query this from an agent

The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.