Incident Response Plan

Why Trust Techopedia

What Does Incident Response Plan Mean?

An incident response plan is a document that specifies how an organization will limit the risk of negative consequences should an incident occur that violates an organization's policies for acceptable use.

Advertisements

Incidents are often categorized by the type of risk they pose to continued operations. A cybersecurity incident response plan, for example, provides step-by-step instructions for what employees should do in response to the following types of events:

The purpose of an incident response plan is to clearly document responsibilities and linear workflows so everyone is on the same page should an event occur.

Techopedia Explains Incident Response Plan

An incident response plan ensures that an incident or breach is resolved or counteracted within the minimum possible time and with the least effect on an organization and its IT systems/environments.

The plan can be a discrete document or included as part of a larger disaster recovery and business continuity plan (BCP).

According to the SANS Institute, every incident response plan should have these six components:

  1. Staff training
  2. Incident identification
  3. Breach containment
  4. Problem eradication
  5. Data recovery
  6. Lessons learned
Advertisements

Related Terms

Margaret Rouse
Technology Expert
Margaret Rouse
Technology Expert

Margaret é uma premiada redatora e professora conhecida por sua habilidade de explicar assuntos técnicos complexos para um público empresarial não técnico. Nos últimos vinte anos, suas definições de TI foram publicadas pela Que em uma enciclopédia de termos tecnológicos e citadas em artigos do New York Times, Time Magazine, USA Today, ZDNet, PC Magazine e Discovery Magazine. Ela ingressou na Techopedia em 2011. A ideia de Margaret de um dia divertido é ajudar os profissionais de TI e de negócios a aprenderem a falar os idiomas altamente especializados uns dos outros.