High severityNIST SP 800-614 steps · 4 phases
NIST SP 800-61 Incident Response Lifecycle
NIST SP 800-61r2 4-phase incident response lifecycle; aligned with CSF 2.0 Respond/Recover.
Information note
Informational note: The NIST SP 800-61r2 cycle defines four core phases: Preparation, Detection & Analysis, Containment/Eradication/Recovery, and Post-Incident Activity. Moving to cleanup prematurely—before the true scope of the incident has been determined—increases the risk of missing persistent threats. Organizations should adapt this framework to their own classification criteria and SLA commitments, and regularly test scenarios with tabletop exercises.
1
Preparation
1 steps- Establish response capability and reduce risk
Policy/procedure, communication plan, tool inventory, reduce incident count through common security controls.
2
Detection & Analysis
1 steps- Detect, analyze, and prioritize incidents
Precursor/indicator sources, documentation, prioritization based on functional impact + information impact + recoverability.
3
Containment, Eradication & Recovery
1 steps- Contain, collect evidence, eradicate, restore
Select containment strategy, chain of custody, clean attacker-hosting hosts, restore under monitoring.
4