Choose Rev. 3 when you need incident-response outcomes integrated with CSF 2.0. Choose ISO/IEC 27035 when you need a process model with separate planning and ICT operations guidance.
They can share evidence, but neither publication is a stand-alone certification standard or a source of universal legal reporting deadlines.
Use Rev. 3 as the CSF 2.0 outcome map and as the incident-management process when your organization uses both. The current ISO series is not one document: Part 1:2023 covers principles and process, Part 2:2023 covers planning, preparation, and lessons learned, and Part 3:2020 covers ICT incident response operations. Part 3 still references the 2016 Part 1 phase model, so document how you align it with the 2023 process.
NIST SP 800-61 Rev. 3 is guidance organized as a CSF 2.0 Community Profile, spanning preparation, active response, recovery, and continuous improvement.
Second framework
ISO/IEC 27035
-1:2023 provides principles and a structured process for information-security incident management. It is guidance, not a stand-alone management-system certification.
Use NIST SP 800-61 Rev. 3 when you need a CSF 2.0-based incident response model that ties preparation, detection, response, recovery, and lessons learned into one operating picture.
Use the series for a structured information-security incident-management process. Part 1 is generic across organizations, Part 2 covers plan-and-prepare and learn-lessons work, and Part 3 narrows its operational guidance to ICT incident response rather than non-ICT events such as lost paper records.
Define whether the comparison covers the whole information-security incident process or only ICT operations. Then map that boundary to the Rev. 3 systems, services, suppliers, and organizational outcomes in scope.
Part 2 calls for top-management commitment, an incident-management policy and plan, an Incident Management Team, relationships with internal and external organizations, support, awareness, and training. Part 3 addresses the people, process, and technology used in ICT security operations.
Define the policy owner, Incident Management Team, operational responders, escalation authority, external contacts, and service-provider duties. Map them to Rev. 3 roles without assuming the role names are identical.
Use NIST SP 800-61 Rev. 3 when the trigger is a need to prepare for, detect, respond to, recover from, or learn from a cybersecurity incident within a CSF 2.0-based program.
Use the ISO process to detect and report an information-security event, assess it, decide whether it is an incident, respond, and learn lessons. Planning changes, exercises, team evaluations, and actual incidents can also trigger process improvement.
Write event-to-incident criteria once, then record how the ISO assessment decision corresponds to Rev. 3's declaration of an incident when adverse events meet defined incident criteria.
For NIST SP 800-61 Rev. 3, turn the guidance into concrete incident response duties such as preparation, detection, response, recovery, roles, evidence handling, communication, and lessons learned.
The ISO series covers governance and preparation, event detection and reporting, assessment and decision, response, and lessons learned. Part 3 adds ICT triage, analysis, containment, eradication, recovery, and conclusion.
Keep the ISO process step and the Rev. 3 outcome on each task. One operational action may support both, but the mapping should show the distinct source and completion criterion.
NIST SP 800-61 Rev. 3 evidence should show the incident facts, the response actions taken, the records preserved, and the decisions made at each stage.
ISO evidence can include the policy and plan, team and contact records, training, event reports, assessment and classification decisions, triage and analysis records, response actions, communications, containment and eradication results, recovery checks, closure records, and documented improvements.
Maintain one evidence index with the source part and process step, Rev. 3 outcome, owner, timestamp, artifact, integrity requirement, and approval state.
Rev. 3 was published in April 2025 and supersedes Rev. 2. It supplies no universal reporting timer, recovery window, or certification cycle; those must be defined or overlaid from other authorities.
provides process guidance rather than one universal notification, containment, or recovery deadline. The organization sets operational targets and overlays legal, regulatory, contractual, sector, and customer clocks.
Use the same event timestamp across both frameworks, but maintain separate deadlines for triage, escalation, external notification, containment, recovery, closure, retention, and review.
For NIST SP 800-61 Rev. 3, identify the authority or reviewer that will judge whether the incident response program is adequate and what proof they expect.
-1 is guidance rather than a stand-alone certifiable management-system standard. Assurance usually comes from internal review, customer or contract assessment, or a broader information-security management system.
supplies a process and more detailed planning and ICT operational guidance. Its records can support Rev. 3 when the incident, boundary, decision, action, owner, and evidence-quality need match.
Cross-reference shared records and add a bridge note for differences in terminology, phase structure, edition, scope, or approval. Do not claim automatic equivalence.
Choose NIST SP 800-61 Rev. 3 first when you want a CSF 2.0-based incident response playbook that integrates preparation, detection, response, recovery, and lessons learned into one operating model.
When both apply, adopt one operating workflow and annotate each step with its Rev. 3 outcome and ISO part. Keep legal reporting and assurance claims outside the crosswalk unless a separate authority supports them.
Use NIST SP 800-61 Rev. 3 when you need a CSF 2.0-based incident response model that ties preparation, detection, response, recovery, and lessons learned into one operating picture.
Use the series for a structured information-security incident-management process. Part 1 is generic across organizations, Part 2 covers plan-and-prepare and learn-lessons work, and Part 3 narrows its operational guidance to ICT incident response rather than non-ICT events such as lost paper records.
Define whether the comparison covers the whole information-security incident process or only ICT operations. Then map that boundary to the Rev. 3 systems, services, suppliers, and organizational outcomes in scope.
Part 2 calls for top-management commitment, an incident-management policy and plan, an Incident Management Team, relationships with internal and external organizations, support, awareness, and training. Part 3 addresses the people, process, and technology used in ICT security operations.
Define the policy owner, Incident Management Team, operational responders, escalation authority, external contacts, and service-provider duties. Map them to Rev. 3 roles without assuming the role names are identical.
Use NIST SP 800-61 Rev. 3 when the trigger is a need to prepare for, detect, respond to, recover from, or learn from a cybersecurity incident within a CSF 2.0-based program.
Use the ISO process to detect and report an information-security event, assess it, decide whether it is an incident, respond, and learn lessons. Planning changes, exercises, team evaluations, and actual incidents can also trigger process improvement.
Write event-to-incident criteria once, then record how the ISO assessment decision corresponds to Rev. 3's declaration of an incident when adverse events meet defined incident criteria.
For NIST SP 800-61 Rev. 3, turn the guidance into concrete incident response duties such as preparation, detection, response, recovery, roles, evidence handling, communication, and lessons learned.
The ISO series covers governance and preparation, event detection and reporting, assessment and decision, response, and lessons learned. Part 3 adds ICT triage, analysis, containment, eradication, recovery, and conclusion.
Keep the ISO process step and the Rev. 3 outcome on each task. One operational action may support both, but the mapping should show the distinct source and completion criterion.
NIST SP 800-61 Rev. 3 evidence should show the incident facts, the response actions taken, the records preserved, and the decisions made at each stage.
ISO evidence can include the policy and plan, team and contact records, training, event reports, assessment and classification decisions, triage and analysis records, response actions, communications, containment and eradication results, recovery checks, closure records, and documented improvements.
Maintain one evidence index with the source part and process step, Rev. 3 outcome, owner, timestamp, artifact, integrity requirement, and approval state.
Rev. 3 was published in April 2025 and supersedes Rev. 2. It supplies no universal reporting timer, recovery window, or certification cycle; those must be defined or overlaid from other authorities.
provides process guidance rather than one universal notification, containment, or recovery deadline. The organization sets operational targets and overlays legal, regulatory, contractual, sector, and customer clocks.
Use the same event timestamp across both frameworks, but maintain separate deadlines for triage, escalation, external notification, containment, recovery, closure, retention, and review.
For NIST SP 800-61 Rev. 3, identify the authority or reviewer that will judge whether the incident response program is adequate and what proof they expect.
-1 is guidance rather than a stand-alone certifiable management-system standard. Assurance usually comes from internal review, customer or contract assessment, or a broader information-security management system.
supplies a process and more detailed planning and ICT operational guidance. Its records can support Rev. 3 when the incident, boundary, decision, action, owner, and evidence-quality need match.
Cross-reference shared records and add a bridge note for differences in terminology, phase structure, edition, scope, or approval. Do not claim automatic equivalence.
Choose NIST SP 800-61 Rev. 3 first when you want a CSF 2.0-based incident response playbook that integrates preparation, detection, response, recovery, and lessons learned into one operating model.
When both apply, adopt one operating workflow and annotate each step with its Rev. 3 outcome and ISO part. Keep legal reporting and assurance claims outside the crosswalk unless a separate authority supports them.
When should teams use NIST SP 800-61 Rev. 3 first versus ISO/IEC 27035 first?
Use NIST SP 800-61 Rev. 3 first when you need a CSF 2.0-based incident response model that ties preparation, detection, response, recovery, and lessons learned into one operating path.
Use first when you need incident management process guidance centered on defining and running an information security incident management process.
Use both when one set of evidence can support two clearly separated cited claims.
How do the CSF 2.0 profile and ISO incident-management process differ?
Rev. 3 spreads incident-response outcomes across all six CSF 2.0 Functions: Govern, Identify, and Protect support preparation and improvement; Detect, Respond, and Recover cover active incident work. uses an incident-management phase model and provides more detailed guidance for planning, teams, relationships, training, triage, analysis, containment, eradication, recovery, conclusion, and lessons learned.
In the ISO process, a reported information security event is assessed before it is classified as an information security incident. Part 3 then narrows its operational guidance to ICT incidents; it expressly excludes non-ICT response operations such as the loss of paper records. Define the event-to-incident criteria, severity scheme, escalation authority, and the handoff for non-ICT events in the organization's own policy and plan.
Choose the primary structure: CSF 2.0 outcomes or the process.
Assign an Incident Management Team to manage the end-to-end capability and an incident response team or equivalent operational roles to perform response work; record authority to disconnect or shut down critical systems.
Map each control, procedure, role, event report, assessment decision, response action, closure approval, and improvement record to a specific outcome or process step.
Reassess the process after exercises, team evaluations, actual incidents, material service or threat changes, and lessons-learned findings. Test changed procedures before they go live.
Overlay legal, regulatory, contractual, and customer notification duties because neither publication supplies a universal reporting clock.
Supports the NIST side by identifying SP 800-61 Rev. 3 as April 2025 guidance for incident preparation, detection, response, recovery, and lessons learned.
"incident response recommendations and considerations"