NIST SP 800-61 Rev. 3
Respond (RS): incident response – NIST SP 800-61 Rev. 3

NIST SP 800-61 Rev. 3 RS.MI-02: RS.MI-02 Incidents eradicated across all affected hosts and services

CSF 2.0 outcome: incidents are eradicated. Priority High. N1: eradication mitigates the incident's effects after containment, removing persistence mechanisms and entry points, for example deleting malware, disabling breached accounts and mitigating every exploited vulnerability. R1: identify all affected hosts and services so that all flaws and weaknesses can be remediated. C1: consider configuring security technologies and other technologies' security features to perform some eradication automatically. C2: consider authorizing ISPs and cloud providers to eradicate certain incidents automatically on the organization's behalf. R2: let handlers select and perform eradication actions manually instead of or as well as automated measures.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Respond (RS): incident response – NIST SP 800-61 Rev. 3

Query this from an agent

The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.