Which CSIRT roles should teams define under NIST SP 800-61 Rev. 3?
Define csirt roles by naming the operating role, scope, authority, evidence artifact, and source-linked requirement before using it in a live workflow.
NIST SP 800-61 Rev. 3 says incident response roles and responsibilities can include leadership, incident handlers, technology professionals, legal, public affairs and media relations, human resources, physical security and facilities management, asset owners, and third parties.
- Leadership oversees incident response, allocates funding, and may approve high-impact response actions.
- Incident handlers verify incidents, collect and analyze data and evidence, prioritize response activities, and limit damage.
- Technology professionals, legal, public affairs and media relations, human resources, and physical security and facilities management support response and recovery as needed.
- Asset owners help set response and recovery priorities for affected assets and receive status updates.
- Third parties, such as MSSPs, cloud service providers, ISPs, business partners, and law enforcement agencies, may support incident response when the organization needs them.
Primary NIST final publication page for SP 800-61 Rev. 3.
DOI for the April 2025 incident response publication.
Primary NIST source for the CSF Core, Organizational Profiles, Tiers, and implementation approach.