Objective:
Recommended Control 1:
Incident Response Plans (IRP) outline actions to take in response
to an information security incident
incidents
national policy requirements for incident reporting (see
Chapter 10 – Information Security Incidents).
Agencies should include the following content within their IRP:
clear definitions of the types of information security
incidents that are likely to be encountered
the expected response to each information security
incident type
the authority within the agency that is responsible for
responding to information security incidents
the criteria by which the responsible authority would
initiate or request formal police investigations of an
information security incident
which other agencies or authorities need to be informed in
the event of an investigation being undertaken
the details of the system contingency measures or a
reference to these details if they are located in a separate
document
The purpose of developing an IRP is to ensure that information security incidents are appropriately
managed. In most situations the aim of the response will be to contain the incident and prevent the
information security incident from escalating. The preservation of any evidence relating to the
information security incident for criminal, forensic and process improvement purposes is also an
important consideration.
36