NIST SP 800-61 Rev. 3
NIST's incident response guidance, rewritten in April 2025 as a CSF 2.0 Community Profile: every CSF 2.0 Function, Category and Subcategory given an incident-response priority, with recommendations, considerations and notes on the outcomes that matter for preparing for, detecting, responding to and recovering from cybersecurity incidents, and lessons learned fed back through the Improvement Category. Supersedes the 2012 Computer Security Incident Handling Guide (Rev. 2), withdrawn on 3 April 2025.
NIST SP 800-61 Rev. 3 is a compliance framework from United States (NIST, FISMA authority); voluntary for non-federal organizations with 6 domains and 72 controls that map to 132 other frameworks. The largest domains are Identify (ID): preparation and lessons learned – NIST SP 800-61 Rev. 3 (18 controls), Respond (RS): incident response – NIST SP 800-61 Rev. 3 (16 controls), Detect (DE): incident response – NIST SP 800-61 Rev. 3 (13 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (6)
Detect (DE): incident response – NIST SP 800-61 Rev. 3
| Code | Title |
|---|---|
| nist-sp-800-61-rev-3::DE.AE | DE.AE Adverse event analysis filtered by technology and aimed at early detection |
| nist-sp-800-61-rev-3::DE.AE-02 | DE.AE-02 Log events analyzed with SIEM or SOAR tools, current CTI and manual review |
| nist-sp-800-61-rev-3::DE.AE-03 | DE.AE-03 Logs centralized and events correlated across sources |
| nist-sp-800-61-rev-3::DE.AE-04 | DE.AE-04 Impact and scope of adverse events estimated and refined |
| nist-sp-800-61-rev-3::DE.AE-06 | DE.AE-06 Alerts and findings delivered to the SOC and responders, with ticketing |
| nist-sp-800-61-rev-3::DE.AE-07 | DE.AE-07 CTI, context and vulnerability disclosures integrated into analysis |
| nist-sp-800-61-rev-3::DE.AE-08 | DE.AE-08 Incidents declared by applying incident criteria |
| nist-sp-800-61-rev-3::DE.CM | DE.CM Continuous monitoring of all asset types at all times, tuned and informed by threat information |
| nist-sp-800-61-rev-3::DE.CM-01 | DE.CM-01 Networks and network services monitored, including rogue networks |
| nist-sp-800-61-rev-3::DE.CM-02 | DE.CM-02 Physical environment monitored for access attempts, movement and tampering |
| nist-sp-800-61-rev-3::DE.CM-03 | DE.CM-03 Personnel activity and technology usage monitored for anomalies |
| nist-sp-800-61-rev-3::DE.CM-06 | DE.CM-06 External service provider activity monitored, including remote administration |
| nist-sp-800-61-rev-3::DE.CM-09 | DE.CM-09 Computing environments monitored for malware, credential attacks, drift, tampering and endpoint health |
Govern (GV): preparation – NIST SP 800-61 Rev. 3
| Code | Title |
|---|---|
| nist-sp-800-61-rev-3::GV.OC-03 | GV.OC-03 Legal, regulatory and contractual requirements include incident response requirements |
| nist-sp-800-61-rev-3::GV.OC-04 | GV.OC-04 External dependencies on the organization inform response priorities |
| nist-sp-800-61-rev-3::GV.OC-05 | GV.OC-05 The organization's own dependencies on external resources inform response priorities |
| nist-sp-800-61-rev-3::GV.OV-01 | GV.OV-01 Past incidents inform adjustments to strategy and direction |
| nist-sp-800-61-rev-3::GV.OV-02 | GV.OV-02 Risks from past incidents considered when reviewing the strategy |
| nist-sp-800-61-rev-3::GV.PO | GV.PO Cybersecurity policies include an incident response policy |
| nist-sp-800-61-rev-3::GV.RM-03 | GV.RM-03 Incident decisions informed by enterprise risk, not cybersecurity risk alone |
| nist-sp-800-61-rev-3::GV.RM-06 | GV.RM-06 A standard risk method used to prioritize incidents and set escalation criteria |
| nist-sp-800-61-rev-3::GV.RR | GV.RR Cybersecurity roles, responsibilities and authorities include incident response |
| nist-sp-800-61-rev-3::GV.RR-01 | GV.RR-01 Leadership accountable for cybersecurity risk, including incident response |
| nist-sp-800-61-rev-3::GV.RR-02 | GV.RR-02 Incident response roles documented in policy and given the authority they need |
| nist-sp-800-61-rev-3::GV.SC-05 | GV.SC-05 Supplier requirements include incident disclosure and information sharing |
| nist-sp-800-61-rev-3::GV.SC-08 | GV.SC-08 Relevant suppliers included in incident planning, response and recovery |
Identify (ID): preparation and lessons learned – NIST SP 800-61 Rev. 3
| Code | Title |
|---|---|
| nist-sp-800-61-rev-3::ID.AM-01 | ID.AM-01 Current, automatically updated hardware inventories available to responders |
| nist-sp-800-61-rev-3::ID.AM-02 | ID.AM-02 Current, automatically updated software, service and system inventories available to responders |
| nist-sp-800-61-rev-3::ID.AM-03 | ID.AM-03 Network data flow representations maintained to detect malicious flows |
| nist-sp-800-61-rev-3::ID.AM-04 | ID.AM-04 Current inventories of supplier-provided services available to responders |
| nist-sp-800-61-rev-3::ID.AM-05 | ID.AM-05 Asset priorities and dependencies direct protection, detection, response and recovery |
| nist-sp-800-61-rev-3::ID.AM-07 | ID.AM-07 Data inventories show what data an incident may have involved |
| nist-sp-800-61-rev-3::ID.AM-08 | ID.AM-08 Life cycle management accounts for cybersecurity and keeps inventories current |
| nist-sp-800-61-rev-3::ID.IM-01 | ID.IM-01 Incident response program periodically evaluated |
| nist-sp-800-61-rev-3::ID.IM-02 | ID.IM-02 Improvements identified from incident response tests and exercises |
| nist-sp-800-61-rev-3::ID.IM-03 | ID.IM-03 Lessons learned from incident response and recovery feed improvement |
| nist-sp-800-61-rev-3::ID.IM-04 | ID.IM-04 Incident response, vulnerability management and continuity plans maintained and synchronized |
| nist-sp-800-61-rev-3::ID.RA-01 | ID.RA-01 All types of known vulnerabilities understood for risk decisions |
| nist-sp-800-61-rev-3::ID.RA-02 | ID.RA-02 Cyber threat intelligence received and used for incident response |
| nist-sp-800-61-rev-3::ID.RA-03 | ID.RA-03 Internal and external threats identified in routine operations and from CTI |
| nist-sp-800-61-rev-3::ID.RA-04 | ID.RA-04 Impacts and likelihoods recorded to determine risk |
| nist-sp-800-61-rev-3::ID.RA-05 | ID.RA-05 Existing risk estimation mechanisms used for incident response |
| nist-sp-800-61-rev-3::ID.RA-06 | ID.RA-06 Criteria guide risk response decisions to prevent incidents and recurrence |
| nist-sp-800-61-rev-3::ID.RA-08 | ID.RA-08 Processes for receiving and acting on vulnerability disclosures |
Protect (PR): preparation – NIST SP 800-61 Rev. 3
| Code | Title |
|---|---|
| nist-sp-800-61-rev-3::PR.AT-02 | PR.AT-02 Role-based training includes incident-related responsibilities |
| nist-sp-800-61-rev-3::PR.DS-11 | PR.DS-11 Backups created, protected, maintained and tested for recovery |
| nist-sp-800-61-rev-3::PR.PS-04 | PR.PS-04 Log records generated and kept for detection, response and recovery |
| nist-sp-800-61-rev-3::PR.PS-06 | PR.PS-06 Secure development practices cover responding to vulnerabilities and incidents in released software |
Recover (RC): incident response – NIST SP 800-61 Rev. 3
| Code | Title |
|---|---|
| nist-sp-800-61-rev-3::RC.CO-03 | RC.CO-03 Recovery progress shared securely with leadership and suppliers under agreed protocols |
| nist-sp-800-61-rev-3::RC.CO-04 | RC.CO-04 Public recovery updates follow breach procedures and explain prevention steps |
| nist-sp-800-61-rev-3::RC.RP-01 | RC.RP-01 Recovery portion of the plan started and recovery staff briefed on plans and authorizations |
| nist-sp-800-61-rev-3::RC.RP-02 | RC.RP-02 Recovery actions selected by plan criteria and adjusted to reassessed needs |
| nist-sp-800-61-rev-3::RC.RP-03 | RC.RP-03 Backups and restoration assets checked for compromise and corruption before use |
| nist-sp-800-61-rev-3::RC.RP-04 | RC.RP-04 Essential services restored in order and restored systems confirmed with owners and monitored |
| nist-sp-800-61-rev-3::RC.RP-05 | RC.RP-05 Restored assets checked and root causes remediated before production |
| nist-sp-800-61-rev-3::RC.RP-06 | RC.RP-06 End of recovery declared and after-action report prepared |
Respond (RS): incident response – NIST SP 800-61 Rev. 3
| Code | Title |
|---|---|
| nist-sp-800-61-rev-3::RS.AN-03 | RS.AN-03 Sequence of events, actors and root causes of the incident established |
| nist-sp-800-61-rev-3::RS.AN-06 | RS.AN-06 Investigation actions recorded with confidentiality and integrity preserved |
| nist-sp-800-61-rev-3::RS.AN-07 | RS.AN-07 Incident data collected and retained as evidence under preservation procedures |
| nist-sp-800-61-rev-3::RS.AN-08 | RS.AN-08 Incident magnitude estimated by searching known and potential targets |
| nist-sp-800-61-rev-3::RS.CO | RS.CO Mechanisms in place in advance to coordinate with affected parties |
| nist-sp-800-61-rev-3::RS.CO-02 | RS.CO-02 Stakeholders, affected parties, regulators and law enforcement notified as required |
| nist-sp-800-61-rev-3::RS.CO-03 | RS.CO-03 Incident information shared securely with leadership, HR, media and sharing partners |
| nist-sp-800-61-rev-3::RS.MA | RS.MA Incident management by risk factors, not first come, with status tracked |
| nist-sp-800-61-rev-3::RS.MA-01 | RS.MA-01 Incident response plan executed with third parties once an incident is declared |
| nist-sp-800-61-rev-3::RS.MA-02 | RS.MA-02 Incident reports triaged and validated, including third-party reports |
| nist-sp-800-61-rev-3::RS.MA-03 | RS.MA-03 Incidents categorized by type, prioritized and given a response strategy |
| nist-sp-800-61-rev-3::RS.MA-04 | RS.MA-04 Incidents escalated or elevated through tracked status |
| nist-sp-800-61-rev-3::RS.MA-05 | RS.MA-05 Recovery initiation criteria applied, weighing operational disruption |
| nist-sp-800-61-rev-3::RS.MI | RS.MI Containment and eradication criteria set, legal consulted before observing an attacker |
| nist-sp-800-61-rev-3::RS.MI-01 | RS.MI-01 Incidents contained, automatically where configured and manually by handlers |
| nist-sp-800-61-rev-3::RS.MI-02 | RS.MI-02 Incidents eradicated across all affected hosts and services |
Your Compliance Coverage
If you comply with NIST SP 800-61 Rev. 3, you already cover:
NIST Cybersecurity Framework 2.0
84%
67 controls mapped
Compare →OWASP MASVS
6%
5 controls mapped
Compare →OWASP ASVS
6%
5 controls mapped
Compare →+ 129 more: ISO 19650 - Organisation and Digitisation of Information about Buildings and Civil Engineering Works (BIM) (6%), ISO/IEC 27043:2015 (6%)
See all 132 mapped frameworks ↓Maps to 132 other frameworks
Coverage is not the same as your position
This page shows what NIST SP 800-61 Rev. 3 overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.
The Compliance Position Diagnostic, $5,000 fixed, ten business daysWhat is NIST SP 800-61 Rev. 3 and who does it apply to?
NIST SP 800-61 Rev. 3 is a compliance framework from United States (NIST, FISMA authority); voluntary for non-federal organizations with 6 domains and 72 controls. NIST's incident response guidance, rewritten in April 2025 as a CSF 2.0 Community Profile: every CSF 2.0 Function, Category and Subcategory given an incident-response priority, with recommendations, considerations and notes on the outcomes that matter for preparing for, detecting, responding to and recovering from cybersecurity incidents, and lessons learned fed back through the Improvement Category. Supersedes the 2012 Computer Security Incident Handling Guide (Rev. 2), withdrawn on 3 April 2025. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does NIST SP 800-61 Rev. 3 actually require?
NIST SP 800-61 Rev. 3 has 72 controls organised across 6 domains. The largest domains are Identify (ID): preparation and lessons learned – NIST SP 800-61 Rev. 3 (18 controls), Respond (RS): incident response – NIST SP 800-61 Rev. 3 (16 controls), Detect (DE): incident response – NIST SP 800-61 Rev. 3 (13 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of NIST SP 800-61 Rev. 3 do I already cover?
NIST SP 800-61 Rev. 3 maps to 132 other compliance frameworks. The top mapping partners are NIST Cybersecurity Framework 2.0 (84% coverage), OWASP MASVS (6% coverage), OWASP ASVS (6% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement NIST SP 800-61 Rev. 3?
Start your NIST SP 800-61 Rev. 3 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about NIST SP 800-61 Rev. 3 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 72 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 704 frameworks.
Get Started Free →Free forever — no credit card required