How should teams handle severity under NIST SP 800-61 Rev. 3 incident response?
Use severity as a triage label, not a guess. When a report comes in, first verify that a cybersecurity incident has occurred, then estimate the severity of the incident and the level of urgency needed to respond to it.
NIST SP 800-61 Rev. 3 also says incidents should be categorized and prioritized based on scope, likely impact, time-critical nature, and resource availability. In practice, that means severity should be driven by a documented set of risk evaluation factors, not by a vague workflow rule.
- Estimate severity during preliminary review, after confirming the report is a cybersecurity incident.
- Base the decision on factors such as asset criticality, functional impact, data impact, stage of observed activity, threat actor characterization, and recoverability.
- Use the severity result to prioritize response actions, escalation, and when recovery should begin.
- Keep the criteria in the incident response policy so severity decisions are consistent across teams and incidents.
Primary NIST final publication page for SP 800-61 Rev. 3.
DOI for the April 2025 incident response publication.
Primary NIST source for the CSF Core, Organizational Profiles, Tiers, and implementation approach.