# Incident Response Plan

> **Template — adapt before use.** Replace `[bracketed]` placeholders, fill the contact roster, and test the plan at least annually. Starting point only; not legal advice.

| | |
|---|---|
| **Owner** | [Role] |
| **Approved date** | [YYYY-MM-DD] |
| **Review/test cadence** | Annual tabletop minimum |
| **Version** | 1.0 |

Maps to: PCI DSS Req 12.10 · SOC 2 CC7.3–7.5 · ISO 27001 A.5.24–5.26 · HIPAA §164.308(a)(6).

## 1. Purpose & scope
Defines how [Company Name] detects, responds to, and recovers from security incidents affecting its systems or data.

## 2. Roles
- **Incident Commander** — [role]; owns the response for each incident.
- **Technical lead(s)** — investigate and contain.
- **Communications** — [role]; internal and external notifications.
- **Executive sponsor** — [role]; decisions with business/legal impact.
- **On-call / reporting contact** — [email / phone].

## 3. Severity classification
| Severity | Definition | Target response |
|---|---|---|
| SEV-1 | Confirmed breach / major outage / data exposure | Immediate, 24/7 |
| SEV-2 | Significant impact, contained or limited | [1 business hour] |
| SEV-3 | Minor / suspected, no confirmed impact | [1 business day] |

## 4. Process
1. **Detect & report** — anyone reports a suspected incident to [channel]; alerts from monitoring are triaged.
2. **Triage & classify** — assign severity and an Incident Commander.
3. **Contain** — limit spread (isolate hosts, rotate credentials, block access).
4. **Eradicate** — remove the root cause.
5. **Recover** — restore services from known-good state; monitor for recurrence.
6. **Notify** — customers, acquirers/card brands (for cardholder data), and regulators per legal obligations and timelines.
7. **Review** — post-incident review within [5 business days]; capture root cause and corrective actions.

## 5. Notification obligations
_List your applicable obligations and timelines — e.g. GDPR 72-hour authority notice, HIPAA breach notification, card-brand/acquirer reporting, state breach laws, contractual customer SLAs._

## 6. Evidence
Retain incident tickets, timelines, communications, and post-incident review notes — these are the audit evidence that the plan operates.

## 7. Testing
Conduct at least an annual tabletop exercise against a realistic scenario; record participants, scenario, findings, and remediation.

## Revision history
| Version | Date | Author | Change |
|---|---|---|---|
| 1.0 | [YYYY-MM-DD] | [Name] | Initial issue |
