Objective: Recommended Control 1: Incident Response Plans (IRP) outline actions to take in response to an information security incident incidents national policy requirements for incident reporting (see Chapter 10 – Information Security Incidents). Agencies should include the following content within their IRP: clear definitions of the types of information security incidents that are likely to be encountered the expected response to each information security incident type the authority within the agency that is responsible for responding to information security incidents the criteria by which the responsible authority would initiate or request formal police investigations of an information security incident which other agencies or authorities need to be informed in the event of an investigation being undertaken the details of the system contingency measures or a reference to these details if they are located in a separate document The purpose of developing an IRP is to ensure that information security incidents are appropriately managed. In most situations the aim of the response will be to contain the incident and prevent the information security incident from escalating. The preservation of any evidence relating to the information security incident for criminal, forensic and process improvement purposes is also an important consideration. 36

Select target paragraph3