FAQGLOBALNIST SP 800-61 Rev. 3

NIST SP 800-61 Rev. 3 How should teams handle lessons learned under NIST SP 800-61 Rev. 3 incident response

Capture lessons during preparation, detection, response, and recovery, then turn selected lessons into owned, prioritized, testable improvements.

Rev. 3 places lessons learned in the CSF 2.0 Identify Improvement Category. A closing meeting can help, but improvement should not wait until recovery ends.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Questions
2

Structured answer sets in this page tree.

Primary sources
3

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Do not wait for one post-incident meeting. NIST SP 800-61 Rev. 3 routes lessons through the CSF 2.0 Identify Improvement Category (), so teams can communicate a useful lesson as soon as they identify it. Analyze and prioritize each lesson, decide what to change, assign the work, and check whether the change improved the relevant plan, process, safeguard, detection, training, supplier arrangement, or recovery capability. Rev. 3 is April 2025 guidance and does not impose one meeting format, closure deadline, or improvement method.

Search this module

Find a question or answer quickly

2 of 2 questions
Question 1

How should lessons become continuous improvements?

Capture lessons from three sources named in : evaluations such as self-assessments, third-party assessments, and independent audits; security tests and exercises, including work with suppliers and other relevant third parties; and actual operations, including incident response and recovery. Follow-up reports and lessons-learned meetings are useful, especially near the end of a major recovery, but Rev. 3's continuous-improvement model also supports changes while the incident is active.

For each lesson, separate the observation, analysis, and approved improvement. Record what happened, the supporting facts, root or contributing causes where they can be established, affected CSF outcome, risk and recurrence potential, selected action, owner, resources, dependencies, target date, and effectiveness test. A plausible observation may warrant investigation without yet proving a systemic cause.

Prioritize the improvement against other cybersecurity and enterprise risks. Decide whether to correct an immediate operating problem, change the incident-response program, update another cybersecurity activity, accept or defer the risk, or collect more evidence. For example, a missed indicator may lead to a detection change, while a failed supplier handoff may require a contract, contact path, procedure, and joint exercise rather than a technical control.

Make urgent changes during an active incident only through controlled decision and change processes so the team does not disrupt response or destroy evidence. Protect sensitive incident information when communicating the lesson, and give participants enough information to understand the change and their responsibilities.

At recovery closure, prepare an that records the incident, response and recovery actions, and lessons learned. The report is one input to ; it does not show that an improvement worked until the assigned change is implemented and tested.

  • Collect observations from responders, asset owners, leadership, legal, communications, recovery teams, and involved providers.
  • Separate immediate corrections from systemic improvements and prioritize them using the organization's risk method, available resources, and operational dependencies.
  • Update plans, playbooks, detections, safeguards, recovery criteria, training, and coordination arrangements where the lesson applies.
  • Verify implementation and effectiveness through evidence, an assessment, an exercise, operating measures, or a later incident; assignment or document publication alone does not show that the change works.
  • Record a reason and approving owner when an improvement is rejected, deferred, combined with another action, or accepted as residual risk.
  • Communicate the approved change to affected personnel and third parties, then update training and operational material that would otherwise contradict it.
Citations
NIST CSF 2.0 (CSWP 29)

Primary NIST source for the CSF Core, Organizational Profiles, Tiers, and implementation approach.

Question 2

What evidence should support lessons learned under NIST SP 800-61 Rev. 3?

Keep the observation, supporting incident facts, analysis, priority, approved improvement, owner, due date, implementation evidence, and effectiveness result together. Link the improvement to the affected CSF 2.0 outcome and incident record. If the action changes an incident response, business continuity, vulnerability management, or other operational plan, record the plan version, communication or training step, and any exercise used to verify it.

Close an improvement only when the record shows the approved acceptance condition. A completed ticket may prove implementation but not effectiveness. Use the defined test, measure, assessment, exercise result, or later operational evidence to decide whether the change worked and whether another action is needed.

Review open actions on the organization's chosen cadence and reassess them after new incidents, exercises, evaluations, supplier changes, major technology or process changes, or evidence that the control is ineffective. SP 800-61 Rev. 3 recommends periodic plan review and review when significant improvement is needed, but it does not set a universal interval.

  • Observation, source, affected assets or process, and the time it was identified.
  • Root or contributing cause, recurrence risk, affected CSF outcome, and prioritization rationale.
  • Approved action, accountable owner, resources, dependencies, target date, and risk acceptance if deferred.
  • Implementation evidence, effectiveness result, feedback to participants, and closure approval.
  • Changed plan, playbook, control, detection, training, supplier arrangement, or recovery criterion with its version and approval.
  • Effectiveness test, expected result, actual result, reviewer, test date, remaining gap, and follow-up action.
Citations
NIST CSF 2.0 (CSWP 29)

Primary NIST source for the CSF Core, Organizational Profiles, Tiers, and implementation approach.

Primary sources

References and citations

doi.org
Referenced sections
  • Primary NIST source for the CSF Core, Organizational Profiles, Tiers, and implementation approach.
"does not prescribe how outcomes should be achieved"
doi.org
Referenced sections
  • DOI for the April 2025 incident response publication.
"improve the efficiency and effectiveness of their incident detection, response, and recovery activities"
csrc.nist.gov
Referenced sections
  • Supports documenting and prioritizing improvements, updating affected plans and practices, and evaluating whether changes work.
"incident response recommendations and considerations"
Related guides

Explore more topics

Event vs. Incident in NIST SP 800-61 Rev. 3
An event is observable activity. Declare an incident when analysis shows the occurrence meets documented cybersecurity incident criteria.
How should teams handle communications under NIST SP 800-61 Rev. 3 incident response?
Plan incident coordination, formal notifications, public communication, and voluntary information sharing under NIST SP 800-61 Rev. 3.
How should teams handle post-incident evidence under NIST SP 800-61 Rev. 3 incident response?
Preserve incident records, collected data, metadata, integrity, provenance, access controls, and retention decisions under NIST SP 800-61 Rev. 3.
How should teams handle reporting clocks under NIST SP 800-61 Rev. 3 incident response?
NIST SP 800-61 Rev. 3 sets no universal reporting deadline. Build a clock register from each applicable law, regulation, policy, and contract.
How should teams handle severity under NIST SP 800-61 Rev. 3 incident response?
NIST SP 800-61 Rev. 3 sets no universal severity scale. Use documented risk factors to estimate severity and urgency, prioritize response, and reassess.
NIST SP 800-61 Rev. 3 CSF 2.0 Incident Profile Guide
Map NIST SP 800-61 Rev. 3 across CSF 2.0 preparation, Detect-Respond-Recover operations, and continuous improvement without treating the profile as a law or playbook.
NIST SP 800-61 Rev. 3 FAQ: practical implementation questions
Answers on incident declaration, severity, roles, communications, notification clocks, evidence, recovery, and continuous improvement under NIST SP 800-61 Rev. 3.
NIST SP 800-61 Rev. 3 Incident Communications and Escalation
Separate incident coordination, notification, public communication, information sharing, escalation, and elevation, with owners and decision records.
NIST SP 800-61 Rev. 3 Incident Response Playbook Template
Build a scenario-specific incident playbook with declaration criteria, authority, third-party coordination, response evidence, legal overlays, and recovery exit criteria.
NIST SP 800-61 Rev. 3 Incident Severity and Response Targets
Build organization-defined incident severity bands and response targets from NIST risk factors without claiming that NIST prescribes levels or deadlines.
NIST SP 800-61 Rev. 3 Post-Incident Evidence Log Workflow
Preserve incident records and data, document recovery, produce the after-action report, and verify corrective actions under NIST SP 800-61 Rev. 3.
NIST SP 800-61 Rev. 3 vs CISA playbooks: practical side-by-side comparison
Choose NIST SP 800-61 Rev. 3 for an organization-wide incident-response risk model and CISA's playbooks for detailed FCEB incident and vulnerability procedures.
NIST SP 800-61 Rev. 3 vs ISO 22301 business continuity: practical side-by-side comparison
Use NIST SP 800-61 Rev. 3 for cybersecurity incident response and ISO 22301:2019 with Amendment 1:2024 for the business continuity management system.
NIST SP 800-61 Rev. 3 vs ISO/IEC 27035: practical side-by-side comparison
Compare NIST SP 800-61 Rev. 3's CSF 2.0 outcome profile with the ISO/IEC 27035 incident-management process, planning, and ICT response guidance.
NIST SP 800-61 Rev. 3 vs NIS2 incident reporting: practical side-by-side comparison
Use NIST SP 800-61 Rev. 3 to run incident response and the applicable NIS2 national law to assess significant-incident reporting and legal deadlines.
NIST SP 800-61 Rev. 3: escalation decision workflow for incident communications
Run incident coordination, required notifications, public updates, and voluntary information sharing as separate, documented decision streams.
NIST SP 800-61 Rev. 3: What Changed from Rev. 2
See how NIST SP 800-61 Rev. 3 replaced Rev. 2's incident-handling guide with a CSF 2.0 Community Profile and what teams should update.
Using NIST SP 800-61 Rev. 3 for Incident Response
Use NIST SP 800-61 Rev. 3 to assign incident-response outcomes, owners, records, communications, and improvements while tracking binding duties separately.
What should recovery include in a NIST SP 800-61 Rev. 3 incident response process?
Select, authorize, prioritize, and verify recovery actions; check restoration assets and restored systems; confirm service restoration; and document recovery closure.
Which CSIRT roles should teams define under NIST SP 800-61 Rev. 3?
Define incident-response leadership, handlers, technical specialists, legal, communications, HR, facilities, asset owners, and providers under NIST SP 800-61 Rev. 3.