1. Incident response team
- Team lead:
- [Name]
- Technical lead:
- [Name]
- Communications lead:
- [Name]
- Legal advisor:
- [Name]
- Backup contacts:
- [Names]
2. Incident classification
- Critical (immediate response required)
- High (response within 4 hours)
- Medium (response within 24 hours)
- Low (response within 72 hours)
3. Response procedures
Initial assessment
- Identify the incident type and scope
- Determine the severity level
- Activate appropriate response team members
- Document initial findings
Containment
- Isolate affected systems
- Preserve evidence
- Implement temporary fixes
- Document containment actions
Eradication
- Remove threat from systems
- Verify system integrity
- Implement permanent fixes
- Update security controls
Recovery
- Restore systems to normal operation
- Verify system functionality
- Monitor for recurrence
- Document recovery actions
4. Communication plan
Internal communications
- Notify executive team
- Brief affected departments
- Update staff as appropriate
External communications
- Legal requirements for disclosure
- Customer notification procedures
- Media response guidelines
5. Post-incident review
- Document timeline of events
- Analyze response effectiveness
- Identify lessons learned
- Update response procedures
- Schedule follow-up review