1. Authority and Review Include information about the document owner, document reviewer, approver, version control and date of next review or other thresholds to review the plan. For example, a plan could be reviewed on a bi-annual or annual basis, and following a cyber incident, a cyber security exercise, or following organisational changes or changes to policies and other plans, or changes to legislation, regulation or jurisdictional arrangements. For example: Document Control and Review Document Control Author Owner Date created Last reviewed by Last date reviewed Endorsed by and date Next review due date Version Control Version Date of Approval Approved By 0.1 Description of Change Initial Draft 2. Purpose and Objectives Include the purpose and objectives of the CIRP. For example: Purpose of the CIRP (Example) To support a swift and effective response to cyber incidents aligned with the organisation’s security and business objectives. Objectives of the CIRP (Examples) 1. To provide guidance on the steps required to respond to cyber incidents. 2. To outline the roles, responsibilities, accountabilities and authorities of personnel and teams required to manage responses to cyber incidents. 3. To outline legal and regulatory compliance requirements for cyber incidents. 4. To outline internal and external communication processes when responding to cyber incidents. 5. To provide guidance on post incident activities to support continuous improvement. 7

Select target paragraph3