NIST SP 800-61 Rev. 3
Respond (RS): incident response – NIST SP 800-61 Rev. 3

NIST SP 800-61 Rev. 3 RS.MI: RS.MI Containment and eradication criteria set, legal consulted before observing an attacker

CSF 2.0 Category: activities are performed to prevent expansion of an event and mitigate its effects. Priority High. N1: selecting containment and eradication actions is easier and faster with criteria and procedures that consider incident type (for example a cloud services compromise or endpoint ransomware), RS.MA risk factors and the duration of the measure (an emergency workaround removed within hours, a temporary one within two weeks, or permanent), with eradication durations judged the same way. R1: where an attacker is redirected to a sandbox to be observed, usually to gather evidence, which delays containment and eradication, the team should first discuss feasibility with the legal department; the delay can be dangerous because the attacker may escalate access or compromise other systems. These items apply to RS.MI-01 and RS.MI-02.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in Respond (RS): incident response – NIST SP 800-61 Rev. 3

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.