nist-800-61

Provides reference notes on NIST SP 800-61 Rev. 3 incident response guidance.

5|1|Updated Jun 19, 2026
One-click install
npx skills add https://github.com/jgsystemsconsulting/jgs-se-knowledge-packs --skill nist-800-61-jgsystemsconsulting
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: nist-800-61
Source: https://github.com/jgsystemsconsulting/jgs-se-knowledge-packs/tree/main/packs/nist-800-61
Command: npx skills add https://github.com/jgsystemsconsulting/jgs-se-knowledge-packs --skill nist-800-61-jgsystemsconsulting

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve? Systems engineers and security practitioners need NIST SP 800-61 Rev. 3 incident response guidance mid-task but cannot recall the CSF 2.0-aligned life cycle, Community Profile priorities, or role and policy requirements from memory. ## Core Features & Use Cases - Chapter-level reference notes: Six chapters covering the CSF-based IR life cycle, roles and policies, the Table 2 preparation profile, the Table 3 Detect/Respond/Recover profile, and coordination and continuous improvement. - Topic and chapter lookup: Query by topic (e.g., incident declaration, playbooks, lessons learned) or by chapter ch01 through ch06, with a topic index mapping questions to chapters. - Supporting aids: A glossary of IR and CSF terms, twelve implementation patterns with trade-offs, and a cheatsheet of decision rules and common failure smells. - Use Case: When migrating from SP 800-61r2 to a CSF 2.0-aligned IR program, ask for the Table 1 phase mapping and Community Profile priorities to plan the transition. ## Quick Start Ask the agent to explain the NIST SP 800-61r3 incident response life cycle and how it maps to CSF 2.0 Functions.

Frequently Asked Questions about nist-800-61

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I align incident response with NIST CSF 2.0?

Use the CSF-based IR life cycle from SP 800-61r3: Govern, Identify, and Protect form the preparation layer, Detect, Respond, and Recover form the active response layer, and ID.IM routes lessons learned continuously into all Functions.

What changed between NIST SP 800-61r2 and r3?

Revision 3 supersedes r2 and replaces the four-phase circular handling model with a CSF 2.0 Function-based life cycle. Tactical how-to content moved to CPRT and other resources, while r3 focuses on IR as cybersecurity risk management.

What is the CSF Community Profile for incident response?

It is a two-table baseline of CSF outcomes for cyber incident risk management. Table 2 covers preparation and lessons learned (GV/ID/PR plus ID.IM), and Table 3 covers Detect, Respond, and Recover, with High/Medium/Low priorities and R/C/N annotations.

Does this pack replace the full NIST CSF 2.0 reference?

No. It covers only SP 800-61r3 content and points to the separate nist-csf pack for the full CSF 2.0 subcategory catalog. It also does not reproduce SP 800-61r2 tactical playbooks or provide breach-notification legal advice.

When should I not use SP 800-61r3 guidance?

Do not use it as a packet-level forensics manual, a source of legal breach-notification advice, or a verbatim copy of CISA playbooks. It provides risk-management framing and profile priorities, not step-by-step tactical handling instructions.