Which CSIRT roles should teams define under NIST SP 800-61 Rev. 3?
Start with incident leadership and handling. Leadership oversees the capability, funds it, and may approve high-impact actions such as shutting down or rebuilding a critical service. verify incidents, collect and analyze data and evidence, prioritize work, limit damage, find root causes, and help restore operations.
Add the specialists and owners the incident requires. Technology professionals investigate and restore their systems; legal advises on applicable law, privacy, contracts, and legal consequences; public affairs manages approved media communication; human resources supports personnel matters; facilities teams support physical incidents and access; and asset owners set business and recovery priorities and confirm status.
Choose a staffing model that fits the organization. may be on staff, under contract, or available from a parent organization, specialist provider, business partner, or law-enforcement agency. An organization may combine these approaches. If several internal teams cover different regions or technology segments, coordinate them as one entity so procedures, training, and incident information remain consistent.
When a provider performs part of detection, response, or recovery, document the in the contract. Include information flows, coordination, authority to act, restrictions on sharing or operational decisions, access protections, and the responsibilities that remain with the organization. For example, state whether a cloud provider or internet service provider may automatically isolate a service, whether an MSSP may share sanitized indicators with other customers, and who preserves provider-side logs.
Provider access creates its own risk. NIST notes that service providers may have privileged system access and sensitive data, so plans and contracts should address provider compromise, malicious insiders, confidentiality, and loss of access when the relationship ends. A provider's capability to correlate activity across customers can improve detection, but it does not replace organization-side ownership.
- Leadership oversees incident response, allocates funding, and may approve high-impact response actions.
- verify incidents, collect and analyze data and evidence, prioritize response activities, and limit damage.
- Technology professionals, legal, public affairs and media relations, human resources, and physical security and facilities management support response and recovery as needed.
- Asset owners help set response and recovery priorities for affected assets and receive status updates.
- Third parties, such as MSSPs, cloud service providers, ISPs, business partners, specialist responders, and law enforcement agencies, may support incident response when needed; their authority and availability should not be assumed.
- Assign a lead for each incident or define an equivalent coordination role, then name the backups who cover absence, time-zone gaps, and provider unavailability.
- Write action-level authority for high-risk decisions such as confiscating or disconnecting assets, shutting down or rebuilding services, delaying containment for observation, contacting authorities, approving public statements, and declaring recovery complete.
Supports the listed internal and external roles, their responsibilities, flexible staffing models, and contractual provider boundaries.
DOI for the April 2025 incident response publication.
Primary NIST source for the CSF Core, Organizational Profiles, Tiers, and implementation approach.