Does NIST Cybersecurity Framework require Incident Response?

Yes — 1 provision

Incident Response (RS.AN, RS.MI)

Implements: Incident Response active Effective: Feb 26, 2024
"NIST CSF 2.0 restructured response activities into **analysis and mitigation** subcategories, emphasizing that incident response is a continuous improvement process."

Requirements

RequirementDetails
AnalysisInvestigate incidents to determine scope and impact
MitigationContain and mitigate effects of detected incidents
Sources: NIST CSF 2.0
View Framework View Requirement Coverage matrix