What should recovery include in a NIST SP 800-61 Rev. 3 incident response process?
Recovery should include restoring affected services, validating that the incident is contained, confirming monitoring is in place, communicating status, preserving evidence, and deciding when normal operations can safely resume.
Treat recovery as part of incident response: define the restoration scope, name the accountable owner, attach evidence, and set the next review trigger. Recovery should not be declared complete until essential services are restored in the appropriate order, restored assets have been checked for indicators of compromise, the root causes have been remediated, and normal operating status has been confirmed.
- Define when the event becomes an incident or escalation.
- Preserve records and evidence during response and recovery.
- Feed lessons learned into CSF 2.0 improvement work.
Primary NIST final publication page for SP 800-61 Rev. 3.
DOI for the April 2025 incident response publication.
Primary NIST source for the CSF Core, Organizational Profiles, Tiers, and implementation approach.