11.1. Incident Classification
17
11.2. Cyber Incident Response Team (CIRT) Activation
18
11.3. Investigation Questions
19
11.4. Escalation and De-escalation
19
12. Containment, Evidence Collection and Remediation
19
12.1. Containment
19
12.2. Documentation
20
12.3. Evidence Collection and Preservation
20
12.4. Remediation Action Plan
20
13. Recovery
13.1. Stand Down
14. Learn and Improve
21
21
21
14.1. Post Incident Review
21
14.2. Update and Test Cyber Incident Response Plan
22
14.3. Training
22
APPENDICES
23
Appendix A – Terminology and Definitions
23
Appendix B – Cyber Incident Response Readiness Checklist
24
Appendix C – ACSC Incident Triage Questions
27
Appendix D – Situation Report Template
28
Appendix E – Incident Log Template
29
Appendix F – Evidence Register Template
30
Appendix G – Remediation Action Plan Template
31
Appendix H – Post Incident Review Guide Template
32
Appendix I – Action Register Template
36
Appendix J – Role Cards
37
Appendix K – ACSC Incident Categorisation Framework
38
6