NIST SP 800-61
Containment, Eradication, Recovery

NIST SP 800-61 NISTSP61-5: Containment, Eradication, and Recovery

Execute Containment + Eradication + Recovery per NIST SP 800-61 Rev 2 Section 3.3. Containment Strategy (Section 3.3.1) must be chosen based on (a) potential damage to and theft of resources, (b) need for evidence preservation, (c) service availability requirements, (d) time and resources to implement the strategy, (e) effectiveness of the strategy (partial vs full), (f) duration of the solution (emergency workaround vs temporary vs permanent). Identify Attacking Hosts (Section 3.3.2) via attacker IP address validation + research via search engines + databases + incident response coordination centres + monitor possible communication channels (although NIST 800-61 cautions about attribution complexity). Eradication and Recovery (Section 3.3.4) must (a) eliminate components of the incident (delete malware + disable breached accounts + identify and mitigate exploited vulnerabilities), (b) recover systems to normal operation (restore from clean backup + rebuild systems + replace compromised files + install patches + change passwords + tighten network perimeter security with firewall rulesets and boundary router access control lists), (c) confirm normal functioning + remediate vulnerabilities that enabled the incident, (d) consider higher monitoring level for some time after recovery to verify completeness.

What else in your programme already covers this

This control maps to 287 controls across 93 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • ASD37-06 Email content filtering (Excellent)
  • ASD37-12 Antivirus software with heuristics (Very Good)
  • ASD37-16 Antivirus software with signatures (Limited)
  • ASD37-18 Restrict administrative privileges (Essential)
  • ASD37-20 Multi-factor authentication (Essential)
  • ASD37-23 Protect authentication credentials (Excellent)
  • ASD37-34 Regular backups (Essential)
  • ASD37-35 Business continuity and disaster recovery plans (Very Good)
  • ASD37-36 System recovery capabilities (Very Good)

ISO 27043 · 8 controls

API 1164 · 7 controls

IEC 62443 · 7 controls

ISO 27019 · 7 controls

ISO/SAE 21434 · 7 controls

NIST SP 1800-32 · 7 controls

South Korea ISMS-P · 7 controls

BSI IT-Grundschutz · 6 controls

  • BSI-01 Account management and provisioning
  • BSI-02 Access enforcement and least privilege
  • BSI-03 Multi-factor authentication requirements
  • BSI-04 Remote access controls
  • BSI-05 Wireless access restrictions
  • BSI-14 Vulnerability scanning and management
  • NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
  • NIST-CSF-PR.AA-02 Identities are proofed and bound to credentials based on the context of interactions
  • NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
  • NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process
  • NIST-CSF-RC.RP-06 The end of incident recovery is declared based on criteria, and incident-related documentation is completed
  • NIST-CSF-RS.MA-05 The criteria for initiating incident recovery are applied

ISO 13485 · 5 controls

ISO 27017 · 5 controls

ISO 27018 · 5 controls

  • 3.10 Encrypt Sensitive Data in Transit
  • 3.6 Encrypt Data on End-User Devices
  • 3.7 Establish and Maintain a Data Classification Scheme
  • 3.7.1 Key-management policies and procedures are implemented to include generation of strong cryptographic keys used to protect stored account data
  • FEDRAMP-CP-9 System Backup

NIST SP 800-190 · 5 controls

ISO 27799 · 4 controls

ISO/IEC 27011:2024 · 4 controls

ISO/IEC 29147:2018 · 4 controls

OWASP ASVS · 4 controls

  • OWASPLLM-1 Prompt Injection and System Prompt Leakage (LLM01 + LLM07)
  • OWASPLLM-2 Improper Output Handling and Misinformation (LLM05 + LLM09)
  • OWASPLLM-3 Sensitive Information Disclosure and Privacy (LLM02)
  • OWASPLLM-6 Excessive Agency and Unbounded Consumption (LLM06 + LLM10)

OWASP Top 10:2025 · 4 controls

  • DIQ-1 Data Integration and Interoperability
  • DSO-2 Data Security
  • DSO-3 Data Access Management

ISO/IEC 27010:2015 · 3 controls

ISO/IEC 27031:2011 · 3 controls

ISO/IEC 30111:2019 · 3 controls

  • NISTPF-3 Control-P - Privacy Controls, Data Management, and Disassociated Processing
  • NISTPF-5 Protect-P Access Control (PR.AC-P)
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)
  • OWASPAPI-1 Broken Object Level Authorization (BOLA) and BFLA
  • OWASPAPI-2 Broken Authentication and Token Management
  • OWASPAPI-3 Broken Object Property Level Authorization (BOPLA)
  • DSOMM-1 Culture, Organization, Education, and Governance
  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management
  • DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing

OWASP MASVS · 3 controls

  • OWASPMASVS-3 MASVS-AUTH: Authentication and Authorization
  • OWASPMASVS-6 MASVS-CODE: Code Quality, Build Settings, and Updates
  • OWASPMASVS-7 MASVS-RESILIENCE: Resilience Against Reverse Engineering

ISO 19011 · 2 controls

  • 6.4 Logging and Monitoring
  • 6.5 Preparing and Distributing Audit Report

ISO 22316 · 2 controls

ISO 22317 · 2 controls

ISO 22318 · 2 controls

  • NISTSP34-2 Business Impact Analysis (BIA): Critical Resources, Recovery Priorities
  • NISTSP34-4 Information System Contingency Plan (ISCP) Development
  • PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight
  • PSPF24-4 Physical Security
  • CYB-2 Account Security Measures
  • CYB-5 Cyber Incident Response Plan

APPI · 1 control

  • APPI-A26 Report of Leakage to the Commission and Notification to the Person
  • 4.4.8 Business Continuity and Recovery

Bahrain PDPL · 1 control

  • CJIS-10 System and Information Integrity

FIDO2 / WebAuthn · 1 control

  • UAE-PDPL-Art.6_7 Sensitive personal data and children's data (UAE PDPL Articles 6-7)
  • 62351-8 Role-based access control (RBAC)

ISO 20000-1 · 1 control

ISO 22320:2018 · 1 control

  • 23837-1.7.3 Authentication and classical post-processing

ISO/IEC 27400:2022 · 1 control

ISO/IEC 29134:2023 · 1 control

  • 29134-9.2 Report findings and recommendations

ITIL 4 · 1 control

  • NJDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • NZISM-5 Network Security, System Hardening, and Application Security
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information
  • RUSPD-2 Lawful Basis, Consent, Notice

SWIFT CSCF · 1 control

South Korea PIPA · 1 control

  • TEFCAREC-1 Common Agreement Conformance and Onboarding

Turkey KVKK · 1 control

  • UNGPBHR-2 Pillar II: Corporate Responsibility to Respect Human Rights
  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)
  • USMCADIGITAL-2 Personal Information Protection and Consumer Protection

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 287 it maps to, and the evidence behind each claim, over MCP and REST.