[Withdrawn: Moved to DE.AE-08]
| Publié par | NIST |
|---|---|
| Version | 2.0 |
| Date de publication | 2024-02-26 |
| Langue | en |
| Exigences | 225 |
| Document source | csf.xlsx |
| Clé de plateforme | arcate:compliance:frameworks/nist-csf/2.0 |
Exigences
Information on adverse events is provided to authorized staff and tools
Cyber threat intelligence and other contextual information are integrated into the analysis
Incidents are declared when adverse events meet the defined incident criteria
DE.DP
— Detection Processes
[Withdrawn: Incorporated into other Categories and Functions]
[Withdrawn: Incorporated into GV.RR-02]
[Withdrawn: Incorporated into DE.AE]
[Withdrawn: Incorporated into ID.IM-02]
[Withdrawn: Incorporated into DE.AE-06]
[Withdrawn: Incorporated into ID.IM, ID.IM-03]
RS
— RESPOND
Actions regarding a detected cybersecurity incident are taken
RS.MA
— Incident Management
Responses to detected cybersecurity incidents are managed
The incident response plan is executed in coordination with relevant third parties once an incident is declared
Incident reports are triaged and validated
Incidents are categorized and prioritized
Incidents are escalated or elevated as needed
The criteria for initiating incident recovery are applied
RS.AN
— Incident Analysis
Investigations are conducted to ensure effective response and support forensics and recovery activities
[Withdrawn: Incorporated into RS.MA-02]
[Withdrawn: Incorporated into RS.MA-02, RS.MA-03, RS.MA-04]
Analysis is performed to establish what has taken place during an incident and the root cause of the incident
[Withdrawn: Moved to RS.MA-03]
[Withdrawn: Moved to ID.RA-08]
Actions performed during an investigation are recorded, and the records' integrity and provenance are preserved