NIST SP 800-61 Rev. 3
Respond (RS): incident response – NIST SP 800-61 Rev. 3

NIST SP 800-61 Rev. 3 RS.MA: RS.MA Incident management by risk factors, not first come, with status tracked

CSF 2.0 Category: responses to detected cybersecurity incidents are managed. Priority High. N1: incident management oversees responses to all incidents and shifts priorities and resources as needed; evaluating an incident's overall risk and prioritizing it are perhaps the most critical decisions in the process. R1: because resources are limited, incidents should not be handled first come, first served. R2: triage, prioritization, escalation and elevation, and the decision to start recovery, should all rest on a set of risk evaluation factors, simple or complex according to the organization's needs and maturity. N2: example factors are asset criticality, functional impact, data impact, stage of observed activity, threat actor characterization and recoverability. R3: track the response status of each incident with pertinent information such as a summary, related indicators of compromise, the status and expected time frame of each assigned action, and next steps. These items apply to every RS.MA Subcategory.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in Respond (RS): incident response – NIST SP 800-61 Rev. 3

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.