Skip to main content
U.S. flag

An official website of the United States government

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Guide for Cybersecurity Incident Recovery



Murugiah P. Souppaya, Larry Feldman, Gregory A. Witte


This bulletin summarizes the information presented in NIST SP 800-184: Guide for Cybersecurity Event Recovery. The publication provides organizations with strategic guidance for planning, playbook developing, testing and improvements of recovery planning following a cybersecurity event.
ITL Bulletin -


cyber event, cybersecurity, Cybersecurity Framework (CSF), Cybersecurity Strategy and Implementation Plan (CSIP), metrics, planning, recovery, resilience.


Souppaya, M. , Feldman, L. and Witte, G. (2017), Guide for Cybersecurity Incident Recovery, ITL Bulletin, National Institute of Standards and Technology, Gaithersburg, MD, [online], (Accessed May 30, 2024)


If you have any questions about this publication or are having problems accessing it, please contact

Created February 21, 2017, Updated January 27, 2020