How should teams handle communications under NIST SP 800-61 Rev. 3 incident response?
Use to align internal and external responders on current and planned actions. Use to inform affected customers, employees, partners, regulators, law enforcement, or others when the plan or an applicable requirement calls for it. Route through approved media procedures, and use only with designated stakeholders under response plans and information-sharing agreements.
Prepare these paths before an incident. Procedures should say what must be reported, to whom, and at what times, including initial notices and regular updates. For major incidents, update senior leadership. For malicious insider activity, involve human resources as appropriate. During recovery, continue secure status reporting and coordinate with critical suppliers under contract.
- Coordinate internal and external incident response activities among the people who have incident response roles and responsibilities.
- Notify affected parties when the incident response plan or an applicable law, regulation, policy, or contract requires it; verify the scope, trigger, content, recipient, route, and timing for that specific duty.
- Use public affairs and media relations for public updates, and keep senior leadership informed on major incidents.
- Share cyber threat information only with designated stakeholders, through secure channels, and in line with response plans, contracts, and information-sharing agreements.
- Reassess the communication plan when facts, severity, affected parties, recovery status, legal or contractual duties, or public reporting change.
Supports the four communication categories, advance coordination mechanisms, notification procedures, and communication with designated internal and external stakeholders.
DOI for the April 2025 incident response publication.
Primary NIST source for the CSF Core, Organizational Profiles, Tiers, and implementation approach.