11.1. Incident Classification 17 11.2. Cyber Incident Response Team (CIRT) Activation 18 11.3. Investigation Questions 19 11.4. Escalation and De-escalation 19 12. Containment, Evidence Collection and Remediation 19 12.1. Containment 19 12.2. Documentation 20 12.3. Evidence Collection and Preservation 20 12.4. Remediation Action Plan 20 13. Recovery 13.1. Stand Down 14. Learn and Improve 21 21 21 14.1. Post Incident Review 21 14.2. Update and Test Cyber Incident Response Plan 22 14.3. Training 22 APPENDICES 23 Appendix A – Terminology and Definitions 23 Appendix B – Cyber Incident Response Readiness Checklist 24 Appendix C – ACSC Incident Triage Questions 27 Appendix D – Situation Report Template 28 Appendix E – Incident Log Template 29 Appendix F – Evidence Register Template 30 Appendix G – Remediation Action Plan Template 31 Appendix H – Post Incident Review Guide Template 32 Appendix I – Action Register Template 36 Appendix J – Role Cards 37 Appendix K – ACSC Incident Categorisation Framework 38 6

Select target paragraph3