Does NIST Cybersecurity Framework require Incident Response?
Yes — 1 provision
Incident Response (RS.AN, RS.MI)
"NIST CSF 2.0 restructured response activities into **analysis and mitigation** subcategories, emphasizing that incident response is a continuous improvement process."
Requirements
| Requirement | Details |
|---|---|
| Analysis | Investigate incidents to determine scope and impact |
| Mitigation | Contain and mitigate effects of detected incidents |
Sources: NIST CSF 2.0