How should teams handle communications under NIST SP 800-61 Rev. 3 incident response?
Use communications to coordinate the incident response, notify affected customers, employees, partners, regulators, or others when required, share information with designated stakeholders, and handle media or public updates through approved channels.
The standard says these communication activities should follow the organization’s response plans and information sharing agreements, and notifications should comply with the current incident notification-related laws and regulations that apply to the organization.
- Coordinate internal and external incident response activities among the people who have incident response roles and responsibilities.
- Notify affected parties when the incident response plan, laws, regulations, or contracts require it, and follow established procedures for what must be reported and when.
- Use public affairs and media relations for public updates, and keep senior leadership informed on major incidents.
- Share cyber threat information only with designated stakeholders and in line with response plans and information sharing agreements.
- Set a change trigger so the communication decision is reviewed after changes to the incident, the legal or contractual environment, or the affected service, supplier, or product.
Primary NIST final publication page for SP 800-61 Rev. 3.
DOI for the April 2025 incident response publication.
Primary NIST source for the CSF Core, Organizational Profiles, Tiers, and implementation approach.