NIST SP 800-61
Cloud, Third-Party, Threat Intel

NIST SP 800-61 NISTSP61-8: Cloud, Third-Party, and Supply-Chain Incident Handling and Threat Intelligence Integration

Handle cloud, third-party, and supply chain incidents and integrate threat intelligence per NIST SP 800-61 Rev 2 supplemented by NIST SP 800-150 (Cyber Threat Information Sharing) + NIST SP 800-161 (Supply Chain Risk Management). Cloud incident handling must address (a) shared responsibility model per cloud service (SaaS + PaaS + IaaS) with provider-side vs consumer-side responsibilities documented in advance, (b) cloud provider incident reporting channels and SLAs (incident notification timing + scope + format), (c) evidence collection in cloud environments (audit log export + snapshots + identity provider logs + control-plane logs + workload artefacts) where consumer access to underlying infrastructure is limited, (d) cross-tenant isolation verification post-incident, (e) cloud-specific containment (revoke API keys + rotate credentials + isolate accounts + cordon affected workloads + suspend automation), (f) cloud-specific recovery (clean image redeploy + IaC redeploy + verified-clean container image rebuild). Third-party and supply-chain incidents must address (a) supplier incident notification clauses in contracts, (b) joint investigation and information sharing protocols, (c) compromise assessment of supplier-provided components and services. Threat Intelligence Integration must produce continuous intelligence feed consumption + indicator-of-compromise enrichment + retrospective hunting across historical logs when new IoCs emerge.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.