Incident response plan
How security events are reported, assessed, classified, responded to, escalated, recorded and learned from, and who does each step.
How the register reads it
| Also called | incident management procedure, IR plan, incident playbook |
|---|---|
| Family | Resilience and incidents |
| Document type | Plan. The regimes ask for the content, not the label; a line pasted as a standard, procedure, plan or schedule is placed here with the label noted. |
| Expected owner | The information security lead (CISO or ISMS manager). |
| Review cadence | Annual, and after every major incident (the register's default; ISO 27001 5.27 asks that lessons change the plan). |
| On the gap list when | ISO 27001 or DORA or NIS2 or ISO 42001 is ticked and no line resolves to it (ISO 27701 requires it too, inside a parent document, so it does not list it separately). |
| Template | Incident response plan. |
Which standards require it, and what each expects it to contain
7 requiring clauses, 5 regimesShown on a register for the regimes you tick; with none ticked, ISO 27001 is applied. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.
ISO/IEC 27001:2022
ISO 27001 5.24 Information security incident management planning and preparationDefine incident roles, processes and readiness before an incident happens.
What the ISO 27002 guidance expects the document to say: Requires the organisation to plan and prepare for incident handling ahead of time. Incident management processes, plus the roles and responsibilities attached to them, must be defined, put in place and communicated.
Common gap: roles are defined but not formally assigned or approved
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.26 Response to information security incidentsRespond to incidents according to the documented procedures.
What the ISO 27002 guidance expects the document to say: Requires information security incidents to be responded to in accordance with documented procedures, rather than improvised case by case.
Common gap: Plans not tested regularly
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.27 Learning from information security incidentsFeed lessons from incidents back into stronger controls.
What the ISO 27002 guidance expects the document to say: Requires knowledge gained from information security incidents to be fed back into strengthening and improving the information security controls.
Common gap: Root cause analysis limited to symptoms
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO/IEC 27701:2025
ISO 27701 A.3.11 Information security incident management planning and preparationAs part of its information security incident management process the organization shall establish responsibilities and procedures for identifying and recording breaches of PII, and responsibilities and procedures for notifying the required parties of PII breaches, including the timing of notification, and for disclosure to authorities, taking account of applicable legislation and regulation; where a jurisdiction imposes specific breach response and notification regulation, the organization shall be able to demonstrate compliance with it.
Common gap: Security incident process with no PII breach determination step
Source: ISO/IEC 27701:2025
ISO/IEC 42001:2023
ISO 42001 A.8.4 Communication of incidentsThe organization shall determine and document a plan for communicating incidents to relevant interested parties.
Common gap: Is notification timing aligned to regulatory requirements (e.g., EU AI Act, GDPR)?
Source: ISO/IEC 42001:2023
DORA (Regulation (EU) 2022/2554)
DORA Art. 17 ICT-related incident management processFinancial entities shall define, establish and implement an ICT-related incident management process to detect, manage and notify ICT-related incidents, including early warning indicators, procedures to identify/track/log/categorise incidents by priority and severity, roles and responsibilities, and communication plans.
Common gap: No structured incident management process
Source: DORA (Regulation (EU) 2022/2554)
The NIS2 Directive
NIS2 Art. 21(2)(b) Incident handlingIncident handling here is the internal capability to detect, triage, contain, eradicate, recover from and learn from incidents. It is separate from the reporting duty in Article 23: reporting tells the authority what happened, handling is what the entity does about it. The capability needs defined severity levels, an escalation path that reaches decision makers out of hours, named responsibilities, and evidence that it functions rather than exists on paper. Post-incident review matters because it is the link back to Article 21(2)(f), where the effectiveness of the measures is assessed. The classification scheme deserves particular attention, because the same triage has to be able to recognise a significant incident under Article 23(3) and start the 24-hour clock.
Common gap: A response plan that has never been exercised against a realistic scenario
Source: NIS2 Directive
Do this for every document on your list
Paste the list and get this reading for every document at once, with the owner and cadence against each, the clauses quoted, and the documents the regimes expect that the list does not carry. Eight documents free, no account.
Build a register