US government technical guidance
NIST SP 800-61 Rev. 3: Incident Response Recommendations and Considerations for Cybersecurity Risk Management
Published by National Institute of Standards and Technology.
Read the original sourceEvidence
What this source supports
NIST SP 800-61 Rev. 3 integrates incident response with preparation, detection, response, and recovery risk management.
- Locator
- NIST SP 800-61 Rev. 3 PDF pages 8–13, Executive Summary and section 2.1 “Incident Response Life Cycle Model”
- Editorial note
- Broad US federal technical guidance. Qualified owners must decide reporting, notification, evidence handling, and recovery.
NIST says incident-response roles differ by organisation and incident, then gives adaptable examples across leadership, incident handlers, technical professionals, legal, public affairs, human resources, facilities, asset owners, and third parties.
- Locator
- NIST SP 800-61 Rev. 3 PDF pages 13–16, section 2.2 “Incident Response Roles and Responsibilities”
- Editorial note
- The examples are role groups rather than a fixed incident-command structure. The organisation must select qualified owners under its policy and the incident context.
Related advice
Where this source is used
Source handling
Link and citation record
US government publication. Linked and paraphrased only. Qualified security, privacy, legal, insurance, and communications owners must apply it to the incident.