NIST SP 800-61 Rev. 3
Respond (RS): incident response – NIST SP 800-61 Rev. 3

NIST SP 800-61 Rev. 3 RS.MA-03: RS.MA-03 Incidents categorized by type, prioritized and given a response strategy

CSF 2.0 outcome: incidents are categorized and prioritized. Priority High. R1: review incidents in more detail to categorize them by type (for example data breach, ransomware, account takeover, denial of service). R2: prioritize the speed of response to each incident by its scope, likely impact, time-critical nature and resource availability. R3: choose response strategies for active incidents by balancing quick recovery against observing the attacker or investigating more thoroughly. N1: every strategy decision has trade-offs, since observing the attacker or investigating deeply may conflict with returning quickly to normal operations.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Respond (RS): incident response – NIST SP 800-61 Rev. 3

Query this from an agent

The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.