Incident Response Plan
Document control
| Field | Value |
|---|---|
| Document status | Active policy document |
| Owner | Security / Operations |
| Approver | Management |
| Review frequency | Annual or on material change |
| Classification | Customer-shareable |
Purpose
Define how security and privacy incidents are reported, assessed, contained, investigated, remediated, communicated, and closed.
Incident categories
Incidents may include unauthorized access, data exposure, malware, credential compromise, vulnerability exploitation, service disruption, lost device, misconfiguration, insider misuse, vendor incident, or privacy complaint.
Severity classification
Severity should consider data sensitivity, number of affected users/customers, service impact, active exploitation, regulatory/contractual obligations, and containment status.
Response lifecycle
- Identify and report.
- Triage and classify.
- Contain immediate risk.
- Investigate root cause and impact.
- Eradicate and remediate.
- Recover and monitor.
- Communicate to stakeholders where required.
- Conduct post-incident review and track improvements.
Roles
Incident lead coordinates response. Technical owners investigate and remediate. Management/legal/customer owners handle communication obligations. All personnel must report suspected incidents promptly.
Evidence to maintain
Incident ticket, timeline, impacted assets/data, containment actions, forensic notes, communication records, remediation evidence, and post-incident review.