An incident response plan is a formal set of procedures that an organisation has in place to both prepare for and respond to and recover from a cyber security incident. The plan will usually include the assignment of duties and responsibilities, procedure for notifying other parties, notification procedures, escalation procedures, approach to containment and recovery. The incident response plan aims to help organisations respond to an incident in a professional and repetitive manner, to avoid chaos if a security incident. It may include procedures for identifying an incident, assessing the event, reporting the incident containment eradication, system restoration and post-incident audit. The plan may also set out procedures for contacting the appropriate parties in case of various types of event. Regular testing of the incident response plan aids the organisation to monitor any gaps and updates the procedures as systems, business requirements and threats evolve.
Topics