Standards
NIST SP 800-61 Rev. 3NIST

Incident Response Recommendations and Considerations for Cybersecurity Risk Management

Revision 3 realigns incident response with CSF 2.0 and drops the four-phase cycle in favour of integration with risk management. It remains the operational reference for structuring a CSIRT.

Official text

Who it applies to

  • SOC and CSIRT teams
  • Incident response leads
  • Cyber–continuity interfaces

Structuring points

  • Containment always precedes eradication: stop the bleeding before treating
  • Deciding to restore from backup is a risk trade-off, not a procedure
  • Lessons learned must produce dated, owned actions

Preparation, detection, analysis, containment, eradication, recovery and lessons learned.