Back to Frameworks

FIRST CSIRT Services Framework and Standards

International (FIRST — 107 countries)
v2.1 (2024)
7 domains
12 controls

The Forum of Incident Response and Security Teams (FIRST) is the leading global organization for Computer Security Incident Response Teams (CSIRTs) + Product Security Incident Response Teams (PSIRTs) + Vulnerability Coordinators + cybersecurity professionals. FIRST maintains a suite of community-developed standards + frameworks. KEY FIRST STANDARDS: (a) CSIRT SERVICES FRAMEWORK V2.1 (published 2019) - the canonical service-catalog defining 5 SERVICE AREAS + 36 SERVICES that CSIRTs deliver: Information Security Event Management; Information Security Incident Management; Vulnerability Management; Situational Awareness; Knowledge Transfer; (b) COMMON VULNERABILITY SCORING SYSTEM (CVSS) - the industry-standard vulnerability severity metric; CVSS v4.0 published 2023 with revised Base + Threat + Environmental + Supplemental metrics + Macro vector + qualitative severity rating (None/Low/Medium/High/Critical); CVSS v3.1 remains in use for prior advisories; CVSS scores feed into vulnerability management + patch prioritisation + the CISA Known Exploited Vulnerabilities (KEV) Catalog + the NVD; (c) TRAFFIC LIGHT PROTOCOL (TLP) v2.0 - the four-color information-sharing classification system (TLP:RED + TLP:AMBER + TLP:AMBER+STRICT + TLP:GREEN + TLP:CLEAR) used by CSIRTs + ISACs + vendors + governments + replaced TLP v1.0 (TLP:WHITE renamed to TLP:CLEAR in v2.0); (d) INFORMATION EXCHANGE POLICY (IEP) v2.0 - a machine-readable extension of TLP enabling automated policy-driven sharing of cyber threat intelligence; (e) MULTI-PARTY COORDINATED VULNERABILITY DISCLOSURE (MPCVD) GUIDELINES - best practices for coordinated disclosure when multiple affected vendors or affected parties exist; (f) PSIRT SERVICES FRAMEWORK - a parallel Product-team-focused service framework; (g) VULNERABILITY COORDINATION BEST PRACTICES GUIDELINES. FIRST is operated as a non-profit consortium + the standards are publicly available + freely-implementable. Coordination: FIRST standards underpin many national CSIRT regimes (US-CERT + DOE CIRC + CISA + UK NCSC + ENISA + AusCERT + JPCERT/CC + KrCERT/CC + many others) + are referenced in NIST SP 800-61 + ISO/IEC 27035 + NIS2 + CIRCIA + MITRE ATT&CK + the EU Cyber Resilience Act (CRA) vulnerability handling obligations.

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (7)

FIRST: CSIRT Services Framework v2.1 - Foundational and Mandate

1 controls
Controls in the FIRST: CSIRT Services Framework v2.1 - Foundational and Mandate domain of FIRST CSIRT Services Framework and Standards1 controls
CodeTitle
FIRST-CSIRTF-Mandate-QualityCSIRT Services Framework v2.1 - Mandate, Scope and Quality Management

FIRST: Related Standards - CVSS, TLP, IEP, MPCVD and PSIRT Services

6 controls
Controls in the FIRST: Related Standards - CVSS, TLP, IEP, MPCVD and PSIRT Services domain of FIRST CSIRT Services Framework and Standards6 controls
CodeTitle
FIRST-CVSS-v4FIRST Common Vulnerability Scoring System (CVSS) v4.0 (2023) and CVSS v3.1 Legacy
FIRST-IEP-MPCVDFIRST Information Exchange Policy (IEP) v2.0 + Multi-Party Coordinated Vulnerability Disclosure (MPCVD)
FIRST-PSIRT-ServicesFIRST PSIRT Services Framework (2020) - Product Security Incident Response Team Service Catalog
FIRST-Sectoral-NationalCSIRTFIRST Sectoral Coordination - National CSIRTs, ISACs, ENISA, NIS2 + Industry Frameworks
FIRST-Status-PipelineFIRST Standards Pipeline - 2024-2025 Roadmap and Coordination with NIS2, CIRCIA, EU CRA
FIRST-TLP-v2FIRST Traffic Light Protocol (TLP) v2.0 (2022) - Information-Sharing Classification

FIRST: Service Area 1 - Information Security Event Management

1 controls
Controls in the FIRST: Service Area 1 - Information Security Event Management domain of FIRST CSIRT Services Framework and Standards1 controls
CodeTitle
FIRST-CSIRTF-SA1-ISEMService Area 1 - Information Security Event Management (Monitoring, Detection, Triage)

FIRST: Service Area 2 - Information Security Incident Management

1 controls
Controls in the FIRST: Service Area 2 - Information Security Incident Management domain of FIRST CSIRT Services Framework and Standards1 controls
CodeTitle
FIRST-CSIRTF-SA2-ISIMService Area 2 - Information Security Incident Management (Intake, Analysis, Containment, Recovery, Coordination, Crisis)

FIRST: Service Area 3 - Vulnerability Management + Coordinated Disclosure

1 controls
Controls in the FIRST: Service Area 3 - Vulnerability Management + Coordinated Disclosure domain of FIRST CSIRT Services Framework and Standards1 controls
CodeTitle
FIRST-CSIRTF-SA3-VulnMgmtService Area 3 - Vulnerability Management and Coordinated Disclosure

FIRST: Service Area 4 - Situational Awareness and Threat Intelligence

1 controls
Controls in the FIRST: Service Area 4 - Situational Awareness and Threat Intelligence domain of FIRST CSIRT Services Framework and Standards1 controls
CodeTitle
FIRST-CSIRTF-SA4-SituationalAwarenessService Area 4 - Situational Awareness and Threat Intelligence

FIRST: Service Area 5 - Knowledge Transfer (Awareness + Training + Exercises)

1 controls
Controls in the FIRST: Service Area 5 - Knowledge Transfer (Awareness + Training + Exercises) domain of FIRST CSIRT Services Framework and Standards1 controls
CodeTitle
FIRST-CSIRTF-SA5-KnowledgeTransferService Area 5 - Knowledge Transfer (Awareness, Training, Exercises, Advisory)

Your Compliance Coverage

If you comply with FIRST CSIRT Services Framework and Standards, you already cover:

Maps to 60 other frameworks

12 total controls
FFIEC Cybersecurity Assessment Tool (CAT)
3 source controls mapped|3 target controls covered
25%
OWASP Top 10:2025
2 source controls mapped|2 target controls covered
17%
ISO/IEC 30111:2019
2 source controls mapped|4 target controls covered
17%
CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0
2 source controls mapped|3 target controls covered
17%
API 1164
2 source controls mapped|4 target controls covered
17%
ISO/IEC 27400:2022
2 source controls mapped|2 target controls covered
17%
HKMA Cyber Resilience Assessment Framework (C-RAF)
2 source controls mapped|2 target controls covered
17%
ISO/IEC 27011:2024
2 source controls mapped|2 target controls covered
17%
NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements
2 source controls mapped|4 target controls covered
17%
ASD Strategies to Mitigate Cyber Security Incidents
2 source controls mapped|6 target controls covered
17%
OWASP DevSecOps Maturity Model (DSOMM)
2 source controls mapped|3 target controls covered
17%
UK Defence Standard 05-138 - Cyber Security for Defence Suppliers
2 source controls mapped|4 target controls covered
17%
US Consumer Product Safety Commission (CPSC) - Connected Product Safety
1 source controls mapped|3 target controls covered
8%
FBI CJIS Security Policy
1 source controls mapped|1 target controls covered
8%
Spain ENS
1 source controls mapped|3 target controls covered
8%
MITRE D3FEND
1 source controls mapped|1 target controls covered
8%
Ley Orgánica de Protección de Datos Personales (LOPDP)
1 source controls mapped|1 target controls covered
8%
Law No. 172-13 on the Protection of Personal Data
1 source controls mapped|1 target controls covered
8%
India DPDP Act
1 source controls mapped|1 target controls covered
8%
India CERT-In Cyber Security Directions 2022
1 source controls mapped|1 target controls covered
8%
ISO/IEC 27031:2011
1 source controls mapped|6 target controls covered
8%
APRA CPS 234
1 source controls mapped|5 target controls covered
8%
OWASP ASVS
1 source controls mapped|1 target controls covered
8%
APPI
1 source controls mapped|2 target controls covered
8%
US Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards Rule
1 source controls mapped|2 target controls covered
8%
FFIEC IT Examination Handbook
1 source controls mapped|5 target controls covered
8%
Canada ITSG-33 - IT Security Risk Management
1 source controls mapped|1 target controls covered
8%
Annex 11 to EU GMP - Computerised Systems
1 source controls mapped|2 target controls covered
8%
Switzerland FADP
1 source controls mapped|2 target controls covered
8%
AWS Well-Architected Security Pillar
1 source controls mapped|2 target controls covered
8%
ISO/IEC 29147:2018
1 source controls mapped|1 target controls covered
8%
BSI IT-Grundschutz
1 source controls mapped|3 target controls covered
8%
DAMA-DMBOK2 - Data Management Body of Knowledge (2nd Edition)
1 source controls mapped|1 target controls covered
8%
Singapore Cybersecurity Act 2018
1 source controls mapped|1 target controls covered
8%
ISO/IEC 27010:2015
1 source controls mapped|2 target controls covered
8%
APRA CPS 230 Operational Risk Management
1 source controls mapped|4 target controls covered
8%
Barbados Data Protection Act 2019
1 source controls mapped|1 target controls covered
8%
Switzerland New Federal Act on Data Protection (nFADP/nDSG, 2023)
1 source controls mapped|1 target controls covered
8%
Vietnam Law on Cybersecurity (No. 24/2018/QH14)
1 source controls mapped|1 target controls covered
8%
TEFCA - Trusted Exchange Framework and Common Agreement
1 source controls mapped|1 target controls covered
8%
COSO Internal Control - Integrated Framework (2013)
1 source controls mapped|1 target controls covered
8%
US EPA Safe Drinking Water Act (SDWA) - Cybersecurity Requirements
1 source controls mapped|1 target controls covered
8%
Regulation (EU) 2019/1239 on the Maritime Single Window (MSW)
1 source controls mapped|1 target controls covered
8%
Bahrain PDPL
1 source controls mapped|2 target controls covered
8%
ASIS SPC.1-2009 - Organizational Resilience Standard
1 source controls mapped|2 target controls covered
8%
Rwanda Law No. 058/2021 Relating to the Protection of Personal Data
1 source controls mapped|1 target controls covered
8%
Serbia Law on Personal Data Protection (2018)
1 source controls mapped|1 target controls covered
8%
NIST AI Risk Management Framework (AI RMF 1.0)
1 source controls mapped|1 target controls covered
8%
Protective Security Policy Framework (PSPF) Release 2024
1 source controls mapped|1 target controls covered
8%
NIST SP 800-171
1 source controls mapped|1 target controls covered
8%
Azure Security Benchmark
1 source controls mapped|2 target controls covered
8%
Privacy Act 1988 (Australia)
1 source controls mapped|2 target controls covered
8%
Pakistan Personal Data Protection Bill 2023
1 source controls mapped|1 target controls covered
8%
BS 65000:2014 - Guidance on Organizational Resilience
1 source controls mapped|1 target controls covered
8%

Frequently Asked Questions

What is FIRST CSIRT Services Framework and Standards?

FIRST CSIRT Services Framework and Standards is a compliance framework from International (FIRST — 107 countries) with 7 domains and 12 controls. The Forum of Incident Response and Security Teams (FIRST) is the leading global organization for Computer Security Incident Response Teams (CSIRTs) + Product Security Incident Response Teams (PSIRTs) + Vulnerability Coordinators + cybersecurity professionals. FIRST maintains a suite of community-developed standards + frameworks. KEY FIRST STANDARDS: (a) CSIRT SERVICES FRAMEWORK V2.1 (published 2019) - the canonical service-catalog defining 5 SERVICE AREAS + 36 SERVICES that CSIRTs deliver: Information Security Event Management; Information Security Incident Management; Vulnerability Management; Situational Awareness; Knowledge Transfer; (b) COMMON VULNERABILITY SCORING SYSTEM (CVSS) - the industry-standard vulnerability severity metric; CVSS v4.0 published 2023 with revised Base + Threat + Environmental + Supplemental metrics + Macro vector + qualitative severity rating (None/Low/Medium/High/Critical); CVSS v3.1 remains in use for prior advisories; CVSS scores feed into vulnerability management + patch prioritisation + the CISA Known Exploited Vulnerabilities (KEV) Catalog + the NVD; (c) TRAFFIC LIGHT PROTOCOL (TLP) v2.0 - the four-color information-sharing classification system (TLP:RED + TLP:AMBER + TLP:AMBER+STRICT + TLP:GREEN + TLP:CLEAR) used by CSIRTs + ISACs + vendors + governments + replaced TLP v1.0 (TLP:WHITE renamed to TLP:CLEAR in v2.0); (d) INFORMATION EXCHANGE POLICY (IEP) v2.0 - a machine-readable extension of TLP enabling automated policy-driven sharing of cyber threat intelligence; (e) MULTI-PARTY COORDINATED VULNERABILITY DISCLOSURE (MPCVD) GUIDELINES - best practices for coordinated disclosure when multiple affected vendors or affected parties exist; (f) PSIRT SERVICES FRAMEWORK - a parallel Product-team-focused service framework; (g) VULNERABILITY COORDINATION BEST PRACTICES GUIDELINES. FIRST is operated as a non-profit consortium + the standards are publicly available + freely-implementable. Coordination: FIRST standards underpin many national CSIRT regimes (US-CERT + DOE CIRC + CISA + UK NCSC + ENISA + AusCERT + JPCERT/CC + KrCERT/CC + many others) + are referenced in NIST SP 800-61 + ISO/IEC 27035 + NIS2 + CIRCIA + MITRE ATT&CK + the EU Cyber Resilience Act (CRA) vulnerability handling obligations. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does FIRST CSIRT Services Framework and Standards have?

FIRST CSIRT Services Framework and Standards has 12 controls organised across 7 domains. The largest domains are FIRST: Related Standards - CVSS, TLP, IEP, MPCVD and PSIRT Services (6 controls), FIRST: CSIRT Services Framework v2.1 - Foundational and Mandate (1 controls), FIRST: Service Area 1 - Information Security Event Management (1 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does FIRST CSIRT Services Framework and Standards map to?

FIRST CSIRT Services Framework and Standards maps to 60 other compliance frameworks. The top mapping partners are NIST SP 800-171A - Assessing Security Requirements for Controlled Unclassified Information (CUI) (25% coverage), FFIEC Cybersecurity Assessment Tool (CAT) (25% coverage), OWASP Top 10:2025 (17% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with FIRST CSIRT Services Framework and Standards compliance?

Start your FIRST CSIRT Services Framework and Standards compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about FIRST CSIRT Services Framework and Standards requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 12 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 701 frameworks.

Get Started Free →

Free forever — no credit card required