Skip to content
compliancebase

Incident response policy template

SaaS incident response policy template covering severity, roles, evidence, and communications — maps to SOC 2 CC7 and ISO A.5.24–A.5.26 themes.

Download .docx

Incident response policy

**Document control**

| Field | Value | |---|---| | Organization | [COMPANY NAME] | | Policy owner | [OWNER NAME / ROLE] | | Approver | [APPROVER NAME / ROLE] | | Version | [VERSION] | | Effective date | [YYYY-MM-DD] | | Next review | [YYYY-MM-DD] |

**Mapped themes:** SOC 2 CC7.3–CC7.5; ISO/IEC 27001:2022 Annex A.5.24–A.5.28 (educational mapping). Privacy breach clocks (e.g. GDPR Art. 33) may also apply — coordinate with counsel.

1. Purpose

This policy establishes how [COMPANY NAME] prepares for, detects, assesses, responds to, and learns from information security incidents.

2. Scope

Applies to security events and incidents affecting in-scope systems, customer data, and workforce identities.

3. Definitions

  • **Security event:** Observable occurrence that may indicate a security issue.
  • **Security incident:** A security event that compromises (or imminently threatens) confidentiality, integrity, or availability objectives.

4. Policy statements

  • An incident response plan with roles, severity definitions, and communication paths is maintained and tested at least annually.
  • Events are triaged using the severity matrix; decisions (dismiss, watch, declare incident) are recorded.
  • Declared incidents have an incident commander, containment/eradication/recovery steps, and evidence preservation.
  • External notifications (customers, authorities) follow legal and contractual requirements with counsel involvement.
  • Post-incident reviews produce corrective actions with owners and due dates for incidents above [SEVERITY THRESHOLD].
  • On-call and escalation contacts are kept current.

5. Severity (customize)

| Severity | Examples | Initial response | |---|---|---| | SEV1 | Confirmed customer data breach; ransomware in production | Immediate page; executive notify | | SEV2 | Privileged account compromise contained | Same-day commander | | SEV3 | Suspicious auth anomalies under investigation | Business-hours triage |

6. Related documents

Information security policy; Access control policy; Evidence handling runbook [LINK].

---

**Disclaimer:** Educational template only — not legal advice or a substitute for counsel on breach notification. ComplianceBase is vendor-neutral and independent.

Framework versions referenced in this page:

Last verified: July 2026 · Primary sources linked above