17.4
IG2 IG3

Establish and Maintain an Incident Response Process

Asset Type: N/A
Security Function: Respond

Description

Establish and maintain an incident response process that addresses roles and responsibilities, compliance requirements, and a communication plan. Review annually, or when significant enterprise changes occur that could impact this Safeguard.

Implementation Checklist

1
Define response procedures and playbooks
2
Assign response roles and responsibilities
3
Establish response timeframes and SLAs
4
Test response procedures through tabletop or simulation
5
Document lessons learned and update procedures
6
Develop incident response plan and playbooks
7
Define roles, escalation paths, and communication channels
8
Conduct tabletop exercise to validate plan
9
Establish post-incident review process
10
Draft policy/procedure document
11
Obtain stakeholder review and approval
12
Communicate to affected personnel
13
Schedule periodic review and updates

Threats & Vulnerabilities (CIS RAM)

Threat Scenarios

Chaotic Response to Major Security Incident

Confidentiality

During a significant breach, response efforts are uncoordinated because no documented process defines roles, responsibilities, escalation paths, or communication plans, leading to evidence destruction and extended attacker access.

Compliance Violation from Improper Incident Handling

Integrity

The organization violates regulatory requirements during incident response because no documented process addresses compliance obligations for evidence preservation, notification timelines, or reporting requirements.

Public Relations Crisis from Poor Incident Communication

Integrity

Inconsistent and contradictory public statements during a breach erode customer trust because no communication plan was established as part of the incident response process.

Vulnerabilities (When Safeguard Absent)

No Documented Incident Response Process

Without a documented incident response process, the organization has no predefined playbook for roles, responsibilities, compliance requirements, or communication during security incidents.

No Incident Communication Plan

Absence of a communication plan within the incident response process means internal and external communications during incidents are ad hoc, inconsistent, and potentially damaging.

Evidence Requirements

Type Evidence Item Collection Frequency
Document Response procedure/playbook documentation Reviewed bi-annually
Record Response action logs showing procedure execution Per incident
Document Incident response plan and playbooks Reviewed bi-annually
Record Incident reports and post-incident review documentation Per incident
Document Governing policy document (current, approved, communicated) Reviewed annually

Related Policy Templates