Rev. 3 shifts the scope from detailed guidance on detecting, analyzing, prioritizing, and handling incidents to recommendations for incorporating incident response throughout cybersecurity risk management. NIST explains that technical procedures change too often and vary too much by technology, environment, and organization to maintain them in one static publication.
The new lifecycle uses all six CSF 2.0 Functions. Govern, Identify, and Protect support preparation and impact reduction. Detect, Respond, and Recover cover discovery, management, prioritization, containment, eradication, recovery, reporting, notification, and other incident communications. Identify Improvement (ID.IM) receives lessons from every Function so useful changes need not wait for recovery to end.