Side-by-sideGLOBALNIST SP 800-61 Rev. 3

NIST SP 800-61 Rev. 3 vs ISO/IEC 27035: practical side-by-side comparison

Choose Rev. 3 when you need incident-response outcomes integrated with CSF 2.0. Choose ISO/IEC 27035 when you need a process model with separate planning and ICT operations guidance.

They can share evidence, but neither publication is a stand-alone certification standard or a source of universal legal reporting deadlines.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
1

Structured answer sets in this page tree.

Primary sources
6

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Use Rev. 3 as the CSF 2.0 outcome map and as the incident-management process when your organization uses both. The current ISO series is not one document: Part 1:2023 covers principles and process, Part 2:2023 covers planning, preparation, and lessons learned, and Part 3:2020 covers ICT incident response operations. Part 3 still references the 2016 Part 1 phase model, so document how you align it with the 2023 process.

Side-by-side comparison

NIST SP 800-61 Rev. 3 vs ISO/IEC 27035: practical side-by-side comparison

Compare NIST SP 800-61 Rev. 3 and with side-by-side scope, owner, trigger, evidence, cadence, assurance, and decision-rule rows.

Review all sources
First framework
NIST SP 800-61 Rev. 3

NIST SP 800-61 Rev. 3 is guidance organized as a CSF 2.0 Community Profile, spanning preparation, active response, recovery, and continuous improvement.

Second framework
ISO/IEC 27035

-1:2023 provides principles and a structured process for information-security incident management. It is guidance, not a stand-alone management-system certification.

Comparison row 1

Scope and covered activity

NIST SP 800-61 Rev. 3

Use NIST SP 800-61 Rev. 3 when you need a CSF 2.0-based incident response model that ties preparation, detection, response, recovery, and lessons learned into one operating picture.

ISO/IEC 27035

Use the series for a structured information-security incident-management process. Part 1 is generic across organizations, Part 2 covers plan-and-prepare and learn-lessons work, and Part 3 narrows its operational guidance to ICT incident response rather than non-ICT events such as lost paper records.

Operational implication

Define whether the comparison covers the whole information-security incident process or only ICT operations. Then map that boundary to the Rev. 3 systems, services, suppliers, and organizational outcomes in scope.

Comparison row 2

Who must act

NIST SP 800-61 Rev. 3

Rev. 3 names distributed roles including leadership, incident handlers, technology professionals, legal, communications, asset owners, facilities, human resources, and involved third parties.

ISO/IEC 27035

Part 2 calls for top-management commitment, an incident-management policy and plan, an Incident Management Team, relationships with internal and external organizations, support, awareness, and training. Part 3 addresses the people, process, and technology used in ICT security operations.

Operational implication

Define the policy owner, Incident Management Team, operational responders, escalation authority, external contacts, and service-provider duties. Map them to Rev. 3 roles without assuming the role names are identical.

Comparison row 3

Trigger or threshold

NIST SP 800-61 Rev. 3

Use NIST SP 800-61 Rev. 3 when the trigger is a need to prepare for, detect, respond to, recover from, or learn from a cybersecurity incident within a CSF 2.0-based program.

ISO/IEC 27035

Use the ISO process to detect and report an information-security event, assess it, decide whether it is an incident, respond, and learn lessons. Planning changes, exercises, team evaluations, and actual incidents can also trigger process improvement.

Operational implication

Write event-to-incident criteria once, then record how the ISO assessment decision corresponds to Rev. 3's declaration of an incident when adverse events meet defined incident criteria.

Comparison row 4

Core obligations

NIST SP 800-61 Rev. 3

For NIST SP 800-61 Rev. 3, turn the guidance into concrete incident response duties such as preparation, detection, response, recovery, roles, evidence handling, communication, and lessons learned.

ISO/IEC 27035

The ISO series covers governance and preparation, event detection and reporting, assessment and decision, response, and lessons learned. Part 3 adds ICT triage, analysis, containment, eradication, recovery, and conclusion.

Operational implication

Keep the ISO process step and the Rev. 3 outcome on each task. One operational action may support both, but the mapping should show the distinct source and completion criterion.

Comparison row 5

Evidence and records

NIST SP 800-61 Rev. 3

NIST SP 800-61 Rev. 3 evidence should show the incident facts, the response actions taken, the records preserved, and the decisions made at each stage.

ISO/IEC 27035

ISO evidence can include the policy and plan, team and contact records, training, event reports, assessment and classification decisions, triage and analysis records, response actions, communications, containment and eradication results, recovery checks, closure records, and documented improvements.

Operational implication

Maintain one evidence index with the source part and process step, Rev. 3 outcome, owner, timestamp, artifact, integrity requirement, and approval state.

Comparison row 6

Timing and cadence

NIST SP 800-61 Rev. 3

Rev. 3 was published in April 2025 and supersedes Rev. 2. It supplies no universal reporting timer, recovery window, or certification cycle; those must be defined or overlaid from other authorities.

ISO/IEC 27035

provides process guidance rather than one universal notification, containment, or recovery deadline. The organization sets operational targets and overlays legal, regulatory, contractual, sector, and customer clocks.

Operational implication

Use the same event timestamp across both frameworks, but maintain separate deadlines for triage, escalation, external notification, containment, recovery, closure, retention, and review.

Comparison row 7

Enforcement or assurance route

NIST SP 800-61 Rev. 3

For NIST SP 800-61 Rev. 3, identify the authority or reviewer that will judge whether the incident response program is adequate and what proof they expect.

ISO/IEC 27035

-1 is guidance rather than a stand-alone certifiable management-system standard. Assurance usually comes from internal review, customer or contract assessment, or a broader information-security management system.

Operational implication

Escalate when the review route differs because the proof needed for one audience may not satisfy the other.

Comparison row 8

Overlap and reuse

NIST SP 800-61 Rev. 3

Rev. 3 supplies CSF outcomes and recommendations for preparation, active response, recovery, communications, evidence integrity, and improvement.

ISO/IEC 27035

supplies a process and more detailed planning and ICT operational guidance. Its records can support Rev. 3 when the incident, boundary, decision, action, owner, and evidence-quality need match.

Operational implication

Cross-reference shared records and add a bridge note for differences in terminology, phase structure, edition, scope, or approval. Do not claim automatic equivalence.

Comparison row 9

Practical decision rule

NIST SP 800-61 Rev. 3

Choose NIST SP 800-61 Rev. 3 first when you want a CSF 2.0-based incident response playbook that integrates preparation, detection, response, recovery, and lessons learned into one operating model.

ISO/IEC 27035

Choose first when you need a phase-based incident-management process, planning and team guidance, or detailed ICT response operations.

Operational implication

When both apply, adopt one operating workflow and annotate each step with its Rev. 3 outcome and ISO part. Keep legal reporting and assurance claims outside the crosswalk unless a separate authority supports them.

Practical decision rule

When should teams use NIST SP 800-61 Rev. 3 first versus ISO/IEC 27035 first?

  • Use NIST SP 800-61 Rev. 3 first when you need a CSF 2.0-based incident response model that ties preparation, detection, response, recovery, and lessons learned into one operating path.
  • Use first when you need incident management process guidance centered on defining and running an information security incident management process.
  • Use both when one set of evidence can support two clearly separated cited claims.
Section 1

How do the CSF 2.0 profile and ISO incident-management process differ?

Rev. 3 spreads incident-response outcomes across all six CSF 2.0 Functions: Govern, Identify, and Protect support preparation and improvement; Detect, Respond, and Recover cover active incident work. uses an incident-management phase model and provides more detailed guidance for planning, teams, relationships, training, triage, analysis, containment, eradication, recovery, conclusion, and lessons learned.

In the ISO process, a reported information security event is assessed before it is classified as an information security incident. Part 3 then narrows its operational guidance to ICT incidents; it expressly excludes non-ICT response operations such as the loss of paper records. Define the event-to-incident criteria, severity scheme, escalation authority, and the handoff for non-ICT events in the organization's own policy and plan.

  • Choose the primary structure: CSF 2.0 outcomes or the process.
  • Assign an Incident Management Team to manage the end-to-end capability and an incident response team or equivalent operational roles to perform response work; record authority to disconnect or shut down critical systems.
  • Map each control, procedure, role, event report, assessment decision, response action, closure approval, and improvement record to a specific outcome or process step.
  • Reassess the process after exercises, team evaluations, actual incidents, material service or threat changes, and lessons-learned findings. Test changed procedures before they go live.
  • Overlay legal, regulatory, contractual, and customer notification duties because neither publication supplies a universal reporting clock.
Primary sources

References and citations

doi.org
Referenced sections
  • Primary NIST source for the CSF Core, Organizational Profiles, Tiers, and implementation approach.
"does not prescribe how outcomes should be achieved"
doi.org
Referenced sections
  • DOI for the April 2025 incident response publication.
"incident detection, response, and recovery activities"
csrc.nist.gov
Referenced sections
  • Supports the NIST side by identifying SP 800-61 Rev. 3 as April 2025 guidance for incident preparation, detection, response, recovery, and lessons learned.
"incident response recommendations and considerations"
Related guides

Explore more topics

Event vs. Incident in NIST SP 800-61 Rev. 3
An event is observable activity. Declare an incident when analysis shows the occurrence meets documented cybersecurity incident criteria.
How should teams handle communications under NIST SP 800-61 Rev. 3 incident response?
Plan incident coordination, formal notifications, public communication, and voluntary information sharing under NIST SP 800-61 Rev. 3.
How should teams handle lessons learned under NIST SP 800-61 Rev. 3 incident response?
Capture incident-response lessons as they emerge, prioritize them through CSF 2.0 Improvement, and verify changes to plans, controls, training, and recovery.
How should teams handle post-incident evidence under NIST SP 800-61 Rev. 3 incident response?
Preserve incident records, collected data, metadata, integrity, provenance, access controls, and retention decisions under NIST SP 800-61 Rev. 3.
How should teams handle reporting clocks under NIST SP 800-61 Rev. 3 incident response?
NIST SP 800-61 Rev. 3 sets no universal reporting deadline. Build a clock register from each applicable law, regulation, policy, and contract.
How should teams handle severity under NIST SP 800-61 Rev. 3 incident response?
NIST SP 800-61 Rev. 3 sets no universal severity scale. Use documented risk factors to estimate severity and urgency, prioritize response, and reassess.
NIST SP 800-61 Rev. 3 CSF 2.0 Incident Profile Guide
Map NIST SP 800-61 Rev. 3 across CSF 2.0 preparation, Detect-Respond-Recover operations, and continuous improvement without treating the profile as a law or playbook.
NIST SP 800-61 Rev. 3 FAQ: practical implementation questions
Answers on incident declaration, severity, roles, communications, notification clocks, evidence, recovery, and continuous improvement under NIST SP 800-61 Rev. 3.
NIST SP 800-61 Rev. 3 Incident Communications and Escalation
Separate incident coordination, notification, public communication, information sharing, escalation, and elevation, with owners and decision records.
NIST SP 800-61 Rev. 3 Incident Response Playbook Template
Build a scenario-specific incident playbook with declaration criteria, authority, third-party coordination, response evidence, legal overlays, and recovery exit criteria.
NIST SP 800-61 Rev. 3 Incident Severity and Response Targets
Build organization-defined incident severity bands and response targets from NIST risk factors without claiming that NIST prescribes levels or deadlines.
NIST SP 800-61 Rev. 3 Post-Incident Evidence Log Workflow
Preserve incident records and data, document recovery, produce the after-action report, and verify corrective actions under NIST SP 800-61 Rev. 3.
NIST SP 800-61 Rev. 3 vs CISA playbooks: practical side-by-side comparison
Choose NIST SP 800-61 Rev. 3 for an organization-wide incident-response risk model and CISA's playbooks for detailed FCEB incident and vulnerability procedures.
NIST SP 800-61 Rev. 3 vs ISO 22301 business continuity: practical side-by-side comparison
Use NIST SP 800-61 Rev. 3 for cybersecurity incident response and ISO 22301:2019 with Amendment 1:2024 for the business continuity management system.
NIST SP 800-61 Rev. 3 vs NIS2 incident reporting: practical side-by-side comparison
Use NIST SP 800-61 Rev. 3 to run incident response and the applicable NIS2 national law to assess significant-incident reporting and legal deadlines.
NIST SP 800-61 Rev. 3: escalation decision workflow for incident communications
Run incident coordination, required notifications, public updates, and voluntary information sharing as separate, documented decision streams.
NIST SP 800-61 Rev. 3: What Changed from Rev. 2
See how NIST SP 800-61 Rev. 3 replaced Rev. 2's incident-handling guide with a CSF 2.0 Community Profile and what teams should update.
Using NIST SP 800-61 Rev. 3 for Incident Response
Use NIST SP 800-61 Rev. 3 to assign incident-response outcomes, owners, records, communications, and improvements while tracking binding duties separately.
What should recovery include in a NIST SP 800-61 Rev. 3 incident response process?
Select, authorize, prioritize, and verify recovery actions; check restoration assets and restored systems; confirm service restoration; and document recovery closure.
Which CSIRT roles should teams define under NIST SP 800-61 Rev. 3?
Define incident-response leadership, handlers, technical specialists, legal, communications, HR, facilities, asset owners, and providers under NIST SP 800-61 Rev. 3.