US government technical guidance

NIST SP 800-61 Rev. 3: Incident Response Recommendations and Considerations for Cybersecurity Risk Management

Published by National Institute of Standards and Technology.

Published
3 April 2025
Accessed
26 September 2026
Read the original source

Evidence

What this source supports

  1. NIST SP 800-61 Rev. 3 integrates incident response with preparation, detection, response, and recovery risk management.

    Locator
    NIST SP 800-61 Rev. 3 PDF pages 8–13, Executive Summary and section 2.1 “Incident Response Life Cycle Model”
    Editorial note
    Broad US federal technical guidance. Qualified owners must decide reporting, notification, evidence handling, and recovery.
  2. NIST says incident-response roles differ by organisation and incident, then gives adaptable examples across leadership, incident handlers, technical professionals, legal, public affairs, human resources, facilities, asset owners, and third parties.

    Locator
    NIST SP 800-61 Rev. 3 PDF pages 13–16, section 2.2 “Incident Response Roles and Responsibilities”
    Editorial note
    The examples are role groups rather than a fixed incident-command structure. The organisation must select qualified owners under its policy and the incident context.

Source handling

Link and citation record

US government publication. Linked and paraphrased only. Qualified security, privacy, legal, insurance, and communications owners must apply it to the incident.