NIST SP 800-61 NISTSP61-5: Containment, Eradication, and Recovery
Execute Containment + Eradication + Recovery per NIST SP 800-61 Rev 2 Section 3.3. Containment Strategy (Section 3.3.1) must be chosen based on (a) potential damage to and theft of resources, (b) need for evidence preservation, (c) service availability requirements, (d) time and resources to implement the strategy, (e) effectiveness of the strategy (partial vs full), (f) duration of the solution (emergency workaround vs temporary vs permanent). Identify Attacking Hosts (Section 3.3.2) via attacker IP address validation + research via search engines + databases + incident response coordination centres + monitor possible communication channels (although NIST 800-61 cautions about attribution complexity). Eradication and Recovery (Section 3.3.4) must (a) eliminate components of the incident (delete malware + disable breached accounts + identify and mitigate exploited vulnerabilities), (b) recover systems to normal operation (restore from clean backup + rebuild systems + replace compromised files + install patches + change passwords + tighten network perimeter security with firewall rulesets and boundary router access control lists), (c) confirm normal functioning + remediate vulnerabilities that enabled the incident, (d) consider higher monitoring level for some time after recovery to verify completeness.
What else in your programme already covers this
This control maps to 287 controls across 93 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
NIST-CSF-PR.AA-02 Identities are proofed and bound to credentials based on the context of interactions
NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process
NIST-CSF-RC.RP-06 The end of incident recovery is declared based on criteria, and incident-related documentation is completed
NIST-CSF-RS.MA-05 The criteria for initiating incident recovery are applied