{
  "node_id": "nist-sp-800-61r2-incident-handling",
  "title": "Computer Security Incident Handling Guide",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2012-08-01",
  "bluf": "Computer security incident response has become an important component of information technology (IT) programs. Because performing incident response effectively is a complex undertaking, establishing a successful incident response capability requires substantial planning and resources. This publication assists organizations in establishing computer security incident response capabilities and handling incidents efficiently and effectively by providing guidelines for incident handling, particularly for analyzing incident-related data and determining the appropriate response to each incident. The guidelines can be followed independently of particular hardware platforms, operating systems, protocols, or applications.\n\nThe Federal Information Security Management Act (FISMA) requires Federal agencies to establish incident response capabilities. Organizations must create, provision, and operate a formal incident response capability, including creating an incident response policy and plan, developing procedures for incident handling, and establishing relationships with other groups. Federal law also requires Federal agencies to report incidents to the United States Computer Emergency Readiness Team (US-CERT). This guideline is prepared for use by Federal agencies, but may be used by nongovernmental organizations on a voluntary basis. It is intended for computer security incident response teams (CSIRTs), system and network administrators, security staff, and management responsible for preparing for or responding to security incidents.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "fips-200-minimum-security-requirements"
  ],
  "primary_citations_count": 7
}