Incident response policy
**Document control**
| Field | Value | |---|---| | Organization | [COMPANY NAME] | | Policy owner | [OWNER NAME / ROLE] | | Approver | [APPROVER NAME / ROLE] | | Version | [VERSION] | | Effective date | [YYYY-MM-DD] | | Next review | [YYYY-MM-DD] |
**Mapped themes:** SOC 2 CC7.3–CC7.5; ISO/IEC 27001:2022 Annex A.5.24–A.5.28 (educational mapping). Privacy breach clocks (e.g. GDPR Art. 33) may also apply — coordinate with counsel.
1. Purpose
This policy establishes how [COMPANY NAME] prepares for, detects, assesses, responds to, and learns from information security incidents.
2. Scope
Applies to security events and incidents affecting in-scope systems, customer data, and workforce identities.
3. Definitions
- **Security event:** Observable occurrence that may indicate a security issue.
- **Security incident:** A security event that compromises (or imminently threatens) confidentiality, integrity, or availability objectives.
4. Policy statements
- An incident response plan with roles, severity definitions, and communication paths is maintained and tested at least annually.
- Events are triaged using the severity matrix; decisions (dismiss, watch, declare incident) are recorded.
- Declared incidents have an incident commander, containment/eradication/recovery steps, and evidence preservation.
- External notifications (customers, authorities) follow legal and contractual requirements with counsel involvement.
- Post-incident reviews produce corrective actions with owners and due dates for incidents above [SEVERITY THRESHOLD].
- On-call and escalation contacts are kept current.
5. Severity (customize)
| Severity | Examples | Initial response | |---|---|---| | SEV1 | Confirmed customer data breach; ransomware in production | Immediate page; executive notify | | SEV2 | Privileged account compromise contained | Same-day commander | | SEV3 | Suspicious auth anomalies under investigation | Business-hours triage |
6. Related documents
Information security policy; Access control policy; Evidence handling runbook [LINK].
---
**Disclaimer:** Educational template only — not legal advice or a substitute for counsel on breach notification. ComplianceBase is vendor-neutral and independent.