What Computer Security Incident Handling Guide requires
Computer security incident response has become an important component of information technology (IT) programs. Because performing incident response effectively is a complex undertaking, establishing a successful incident response capability requires substantial planning and resources. This publication assists organizations in establishing computer security incident response capabilities and handling incidents efficiently and effectively by providing guidelines for incident handling, particularly for analyzing incident-related data and determining the appropriate response to each incident. The guidelines can be followed independently of particular hardware platforms, operating systems, protocols, or applications. The Federal Information Security Management Act (FISMA) requires Federal agencies to establish incident response capabilities. Organizations must create, provision, and operate a formal incident response capability, including creating an incident response policy and plan, developing procedures for incident handling, and establishing relationships with other groups. Federal law also requires Federal agencies to report incidents to the United States Computer Emergency Readiness Team (US-CERT). This guideline is prepared for use by Federal agencies, but may be used by nongovernmental organizations on a voluntary basis. It is intended for computer security incident response teams (CSIRTs), system and network administrators, security staff, and management responsible for preparing for or responding to security incidents.
Pillar: Cybersecurity · Authority: National Institute of Standards and Technology · Version: 1.0.0 · Last updated:
Primary source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf
SHA-256 integrity: 795d6ed7fe591446cdca4e971d232a312018e062013b4eddd1a7de6376494833
Primary Citations — 7 traced to source
- Executive Summary: Federal law requires Federal agencies to report incidents to the United States Computer Emergency Readiness Team (US-CERT) office within the Department of Homeland Security (DHS).
- Section 2.1: A computer security incident is a violation or imminent threat of violation of computer security policies, acceptable use policies, or standard security practices.
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/nist-sp-800-61r2-incident-handling.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/nist-sp-800-61r2-incident-handling.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/nist-sp-800-61r2-incident-handling
- Back to registry: Browse all 10,090 compliance nodes