# Incident response policy

Source: https://aestech.com.au/policy-templates/#incident-response-policy
Markdown URL: https://aestech.com.au/policy-templates/incident-response-policy.md

Use for ISO 27001 A.5.24 to A.5.28, SOC 2 incident response, PCI DSS 12.10, and security event handling.

Frameworks: ISO 27001, SOC 2, PCI DSS

Use this as a starting point only. Adapt it to your real scope, systems, legal obligations, customer commitments and operating process.

```text
1. Purpose
This policy defines how security events and incidents are reported, assessed, contained, investigated, communicated and reviewed.

2. Severity levels
- SEV1: confirmed breach, active compromise, material customer impact or legal notification likely.
- SEV2: serious security event requiring urgent investigation.
- SEV3: contained event or control failure with limited impact.
- SEV4: low-risk event, alert or near miss.

3. Process
- Detect and report through [channel].
- Triage and classify severity.
- Contain affected accounts, devices, systems or integrations.
- Preserve evidence before changes are made.
- Eradicate root cause and recover service.
- Communicate to internal and external stakeholders as required.
- Complete post-incident review within [x] business days.

4. Evidence
Keep incident tickets, timeline, affected assets, decisions, communications, evidence chain, root cause, corrective actions and closure approval.
```

Full template pack: https://aestech.com.au/policy-templates/policy-pack.md