Policy Register

Incident response plan

How security events are reported, assessed, classified, responded to, escalated, recorded and learned from, and who does each step.

How the register reads it

Also calledincident management procedure, IR plan, incident playbook
FamilyResilience and incidents
Document typePlan. The regimes ask for the content, not the label; a line pasted as a standard, procedure, plan or schedule is placed here with the label noted.
Expected ownerThe information security lead (CISO or ISMS manager).
Review cadenceAnnual, and after every major incident (the register's default; ISO 27001 5.27 asks that lessons change the plan).
On the gap list whenISO 27001 or DORA or NIS2 or ISO 42001 is ticked and no line resolves to it (ISO 27701 requires it too, inside a parent document, so it does not list it separately).
TemplateIncident response plan.

Which standards require it, and what each expects it to contain

7 requiring clauses, 5 regimes

Shown on a register for the regimes you tick; with none ticked, ISO 27001 is applied. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.

ISO/IEC 27001:2022

ISO 27001 5.24 Information security incident management planning and preparation

Define incident roles, processes and readiness before an incident happens.

What the ISO 27002 guidance expects the document to say: Requires the organisation to plan and prepare for incident handling ahead of time. Incident management processes, plus the roles and responsibilities attached to them, must be defined, put in place and communicated.

Evidence an auditor accepts: The incident management process, defining categories, severity, escalation and the decision authority at each level; documented roles and responsibilities for incident handling, including out of hours coverage and named deputies; evidence the process and roles were communicated to those who must act on them
Common gap: roles are defined but not formally assigned or approved
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.26 Response to information security incidents

Respond to incidents according to the documented procedures.

What the ISO 27002 guidance expects the document to say: Requires information security incidents to be responded to in accordance with documented procedures, rather than improvised case by case.

Evidence an auditor accepts: Documented response procedures per incident type, and evidence they were followed in actual incidents; incident records carrying detection, containment, eradication and recovery timestamps and the actions taken at each stage; evidence of decisions taken during response and by whom, including any decision to preserve rather than eradicate
Common gap: Plans not tested regularly
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.27 Learning from information security incidents

Feed lessons from incidents back into stronger controls.

What the ISO 27002 guidance expects the document to say: Requires knowledge gained from information security incidents to be fed back into strengthening and improving the information security controls.

Evidence an auditor accepts: Post incident review records for incidents meeting the defined threshold, with attendees and findings; root cause analysis distinguishing the technical cause from the process or control failure that allowed it; actions arising, with owner, due date and evidence of completion
Common gap: Root cause analysis limited to symptoms
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022

ISO/IEC 27701:2025

ISO 27701 A.3.11 Information security incident management planning and preparation

As part of its information security incident management process the organization shall establish responsibilities and procedures for identifying and recording breaches of PII, and responsibilities and procedures for notifying the required parties of PII breaches, including the timing of notification, and for disclosure to authorities, taking account of applicable legislation and regulation; where a jurisdiction imposes specific breach response and notification regulation, the organization shall be able to demonstrate compliance with it.

Evidence an auditor accepts: Incident procedure with a defined PII breach identification and recording step; notification procedure naming parties, timing and the authority disclosure route per jurisdiction; responsibilities assigned for breach handling
Common gap: Security incident process with no PII breach determination step
Source: ISO/IEC 27701:2025

ISO/IEC 42001:2023

ISO 42001 A.8.4 Communication of incidents

The organization shall determine and document a plan for communicating incidents to relevant interested parties.

Evidence an auditor accepts: Incident communication plan; incident notification records; notification criteria and timing
Common gap: Is notification timing aligned to regulatory requirements (e.g., EU AI Act, GDPR)?
Source: ISO/IEC 42001:2023

DORA (Regulation (EU) 2022/2554)

DORA Art. 17 ICT-related incident management process

Financial entities shall define, establish and implement an ICT-related incident management process to detect, manage and notify ICT-related incidents, including early warning indicators, procedures to identify/track/log/categorise incidents by priority and severity, roles and responsibilities, and communication plans.

Evidence an auditor accepts: Documented ICT incident management process with logging, categorisation and roles
Common gap: No structured incident management process
Source: DORA (Regulation (EU) 2022/2554)

The NIS2 Directive

NIS2 Art. 21(2)(b) Incident handling

Incident handling here is the internal capability to detect, triage, contain, eradicate, recover from and learn from incidents. It is separate from the reporting duty in Article 23: reporting tells the authority what happened, handling is what the entity does about it. The capability needs defined severity levels, an escalation path that reaches decision makers out of hours, named responsibilities, and evidence that it functions rather than exists on paper. Post-incident review matters because it is the link back to Article 21(2)(f), where the effectiveness of the measures is assessed. The classification scheme deserves particular attention, because the same triage has to be able to recognise a significant incident under Article 23(3) and start the 24-hour clock.

Evidence an auditor accepts: The incident handling procedure with severity levels, roles and escalation paths; incident records for a representative period showing detection, containment and recovery times; evidence of out-of-hours coverage and of how escalation reaches decision makers
Common gap: A response plan that has never been exercised against a realistic scenario
Source: NIS2 Directive

Do this for every document on your list

Paste the list and get this reading for every document at once, with the owner and cadence against each, the clauses quoted, and the documents the regimes expect that the list does not carry. Eight documents free, no account.

Build a register

Exercise and test programme · Pandemic response plan