| Scope and covered activity | SP 800-61 Rev. 3 is NIST incident-response guidance for incorporating incident-response recommendations into cybersecurity risk management. Use it to define program scope, owners, evidence, and response practices before mapping operational playbooks. | The two CISA playbooks cover incident response and vulnerability response for FCEB systems, data, and networks. They address agency-CISA communications, coordination between the two response tracks, and common response terminology. | Use Rev. 3 to set the program model and the applicable CISA playbook to run an FCEB procedure. A non-FCEB organization may adapt the broader practices, but federal-only coordination and reporting steps need an independent legal or contractual basis. |
|---|
| Who must act | Rev. 3 distributes work across leadership, incident handlers, technology professionals, legal, communications, human resources, physical security, asset owners, providers, and other internal or external parties as the incident requires. | The affected FCEB agency owns its response while coordinating with CISA and, as applicable, other federal, law-enforcement, intelligence, contractor, and service-provider participants. Each playbook separates agency and CISA actions by phase. | Name the incident commander, vulnerability owner, agency-CISA contact, technical leads, legal and communications contacts, and decision authority. One person may fill several roles, but each decision still needs an accountable owner. |
|---|
| Trigger or threshold | NIST SP 800-61 Rev. 3: use this side when analyzed adverse events meet the defined incident criteria and an incident should be declared. | The Incident Response Playbook applies to confirmed malicious cyber activity when a major incident has been declared or cannot yet be reasonably ruled out. The Vulnerability Response Playbook addresses urgent and high-priority vulnerabilities actively exploited in the wild; the affected agency, CISA, industry partners, or others may identify them. Specific CISA directives can add mandatory actions and deadlines. | Record the trigger, affected FCEB system or service, current incident severity, vulnerability source, applicable directive, decision owner, and time of each federal notification. |
|---|
| Core obligations | Use NIST SP 800-61 Rev. 3 to organize preparation, detection, response, recovery, communications, and lessons-learned improvements across the incident-response program. | The CISA procedures cover preparation, detection and analysis, containment, eradication, recovery, coordination, communication, closure, and lessons learned for incidents, plus identification, evaluation, remediation, verification, and reporting for vulnerabilities. | Keep one crosswalk from each CISA action to its Rev. 3 outcome, named owner, required input, expected record, and completion criterion. Preserve any CISA-specific approval or communication step rather than hiding it inside a generic NIST task. |
|---|
| Evidence and records | Rev. 3 evidence can include declarations, prioritization decisions, investigation and incident data with preserved integrity and provenance, communications, mitigation actions, recovery validation, after-action reports, and improvement records. | CISA evidence includes incident and vulnerability tracking records, impact and scope assessments, action and decision logs, status reports, notifications, remediation verification, recovery validation, closure material, and lessons learned. | Maintain one evidence index with the source step, owner, timestamp, artifact, approval state, and whether it supports Rev. 3, a CISA playbook, or both. Preserve incident-data integrity and provenance when the same evidence is reused. |
|---|
| Timing and cadence | Rev. 3 is final guidance published in April 2025 and supersedes Rev. 2. It sets no universal incident clock; define internal timing targets and track any external legal or contractual clock separately. | The playbooks contain phase-specific timing and escalation instructions, but current binding deadlines can also come from an emergency directive, binding operational directive, OMB policy, or another federal requirement. The playbook's publication date alone does not establish the current deadline for a specific event. | Maintain separate clocks for internal response targets, playbook steps, CISA directives, OMB reporting, contracts, and law. Confirm the current directive before assigning a deadline, and do not transfer a federal timer to a voluntary user. |
|---|
| Enforcement or assurance route | Rev. 3 is not a certification or independent penalty regime. Assurance depends on the authority, federal program, policy, contract, customer, or internal governance that incorporates or evaluates it. | The playbooks implement federal operational procedures under Executive Order 14028 for FCEB information systems. They are not a commercial certification standard. Whether a contractor must follow a step depends on the contract, system responsibility, directive, and agency instructions. | Classify the user as an FCEB agency, a contractor or service provider with a specific obligation, or a voluntary adopter. Record the instrument that makes each step mandatory before presenting it as a duty. |
|---|
| Overlap and reuse | Rev. 3 can supply the outcome structure for CISA procedures, including incident declaration, prioritization, analysis, mitigation, recovery, communication, and improvement. | CISA records can support Rev. 3 outcomes when they cover the same incident, asset boundary, decision, action, owner, and evidence-quality need. Federal coordination records may have no equivalent in a voluntary NIST program. | Cross-reference shared artifacts instead of duplicating them. Add a bridge note when the edition, system boundary, responsible actor, timing, or approval differs. |
|---|
| Practical decision rule | Choose Rev. 3 when the need is an organization-wide, CSF 2.0-aligned incident-response risk-management model rather than one federal operational procedure. | Choose the CISA playbooks first for FCEB execution: agency-CISA coordination, phase checklists, reporting thresholds, vulnerability remediation, and federal response records. | When both apply, use Rev. 3 as the outcome map and the CISA playbook as the procedure. Record where the 2021 playbook's Rev. 2 phase model has been mapped to Rev. 3 rather than claiming a native Rev. 3 alignment. |
|---|