NIST SP 800-61
Policy, Plan, Procedures

NIST SP 800-61 NISTSP61-1: Incident Response Policy, Plan, and Procedures

Establish incident response policy, plan, and procedures per NIST SP 800-61 Rev 2 Chapter 2 (Organizing a Computer Security Incident Response Capability) Section 2.1 and Chapter 3 Section 3.1 (Preparation). Policy must define statement of management commitment + purpose and objectives + scope (to whom and what the policy applies) + roles and responsibilities + reportable incident definitions + reporting requirements + performance measures + reporting and contact forms. Plan must operationalise the policy with mission + strategies and goals + senior management approval + organisational approach + communication path between teams + measures of effectiveness + roadmap for maturing capability. Procedures must include standard operating procedures + technical processes + use of incident response toolkits + checklists. Review policy + plan + procedures at least annually and after every significant incident or substantive change to environment.

What else in your programme already covers this

This control maps to 15 controls across 10 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27043 · 3 controls

ISO/SAE 21434 · 3 controls

  • CPG-2.A Asset Inventory
  • CPG-2.B Prohibit Connection of Unauthorized Devices

ISO/IEC 27010:2015 · 1 control

OWASP ASVS · 1 control

OWASP MASVS · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 15 it maps to, and the evidence behind each claim, over MCP and REST.