[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-169187-en":3,"doc-seo-169187-105":30,"detail-sidebar-cat-1-en-105":92},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":11,"category_id":12,"category_name":13,"doc_title":14,"doc_description":15,"doc_content":16,"file_id":17,"file_url":18,"file_type":19,"file_size":20,"view_count":4,"is_deleted":4,"is_public":11,"is_downloadable":11,"audit_status":11,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":15,"update_tm":28,"read_time":29},169187,8796095462418,"Noah","https://ap-avatar.wpscdn.com/avatar/80000253c1241d02b47?x-image-process=image/resize,m_fixed,w_180,h_180&k=1778826106357471780",1,17,"Forms","Cybersecurity Incident Response Plan Template - Version X - PLAN INFORMATION","Cybersecurity Incident Response Plan template for water and wastewater systems that defines an incident response approach covering preparation, identification, containment, eradication, recovery, and post-incident lessons learned. It establishes responsibilities for the Incident Response Lead or delegate, outlines incident handling roles and processes, and specifies how critical incident data is collected for reporting and coordination with local, state, federal authorities, law enforcement, and external entities. Includes an incident reporting form for documenting breaches and malware and tracking required details for disclosure compliance.","Drinking Water and Wastewater Systems\nCybersecurity Incident Response Plan Template\n[Water/Wastewater System Name]\nCybersecurity Incident Response Plan\nVersion [X]\n[Date]\nThis document and associated electronic files may contain sensitive or confidential information. Please maintain the document/electronic files in a manner that will help safeguard the information.\nPLAN INFORMATION\nAPPROVALS\nThe Incident Response Lead has reviewed this Cybersecurity Incident Response Plan and acknowledges that responsibility for managing the cybersecurity incident is entrusted to the Incident Response Lead or their delegate.\nREVISION HISTORY\nThis Cybersecurity Incident Response Plan has been modified as follows:\nPLAN DISTRIBUTION\nThis Cybersecurity Incident Response Plan has been distributed to the following people:\nTable of Contents\n\u0013 TOC \\o \"2-3\" \\h \\z \\t \"Heading 1,1\" \u0014\u0013 HYPERLINK \\l \"_Toc195530075\" \u00141.0\tPURPOSE\t\u0013 PAGEREF _Toc195530075 \\h \u00141\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc195530076\" \u00142.0\tINCIDENT HANDLING PROCESS\t\u0013 PAGEREF _Toc195530076 \\h \u00141\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc195530077\" \u00142.1.\tIdentification\t\u0013 PAGEREF _Toc195530077 \\h \u00141\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc195530078\" \u00142.2.\tContainment\t\u0013 PAGEREF _Toc195530078 \\h \u00143\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc195530079\" \u00142.3.\tEradication\t\u0013 PAGEREF _Toc195530079 \\h \u00143\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc195530080\" \u00142.4.\tRecovery\t\u0013 PAGEREF _Toc195530080 \\h \u00144\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc195530081\" \u00142.5.\tLessons Learned\t\u0013 PAGEREF _Toc195530081 \\h \u00145\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc195530082\" \u00143.0\tCONTACT LIST\t\u0013 PAGEREF _Toc195530082 \\h \u00146\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc195530083\" \u00144.0\tINCIDENT DATA COLLECTION\t\u0013 PAGEREF _Toc195530083 \\h \u00148\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc195530084\" \u00145.0\tAPPLICABLE REGULATIONS AND REQUIREMENTS\t\u0013 PAGEREF _Toc195530084 \\h \u001411\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc195530085\" \u00146.0\tTESTING AND UPDATES\t\u0013 PAGEREF _Toc195530085 \\h \u001411\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc195530086\" \u0014APPENDIX A – OT/IT System Overview\t\u0013 PAGEREF _Toc195530086 \\h \u001412\u0015\u0015\n\u0015\nPURPOSE\nThis Cybersecurity Incident Response Plan (CIRP) describes the overall approach for responding to cybersecurity incidents at [Water/Wastewater System Name]. It identifies the structure, roles and responsibilities, incident types, and the approach to preparing for, identifying, containing and eradicating threats, recovery, and conducting post-incident lessons learned debriefings.\nThis CIRP applies to all networks, systems, and data, as well as the employees and contractors that access the networks, systems, and data. Staff who may be called upon to lead or participate as part of the Incident Response Team must familiarize themselves with this plan and be prepared to collaborate.\nThis CIRP references and incorporates the following plans, policies, and procedures.\n[Update the table below and list the existing plans, policies, procedures, and other documents that your water system will reference during a cybersecurity incident.]\nINCIDENT HANDLING PROCESS\nDuring and after an incident, the Incident Response Lead/Incident Response Team will follow the Identification, Containment, Eradication, Recover, and Lessons Learned process:\nIdentification\n[Update the table below and insert the specific actions that your utility will follow to identify and determine that a cyber incident is taking place.]\nContainment\n[Update the table below and insert the specific actions that your utility will follow to contain a cyber incident.]\nEradication\n[Update the table below and insert the specific actions that your utility will follow to eradicate a cyber threat.]\nRecovery\n[Update the table below and insert the specific actions that your utility will follow to recover from a cyber incident.]\nLessons Learned\n[Update the table below and insert the specific actions that your utility will follow to capture and document lessons learned following a cyber incident. The overall goal is to learn from incidents and improve response performance while providing reference materials in the event of a similar future incident.]\nCONTACT LIST\nThe following table shows cybersecuri","cbCaie6lv7khbnCj","https://ap.wps.com/l/cbCaie6lv7khbnCj","docx",202716,16,"English","en",105,"# PURPOSE\n# INCIDENT HANDLING PROCESS\n## Identification\n## Containment\n## Eradication\n## Recovery\n## Lessons Learned\n# CONTACT LIST\n# INCIDENT DATA COLLECTION\n# APPLICABLE REGULATIONS AND REQUIREMENTS\n# TESTING AND UPDATES\n# APPENDIX A – OT/IT System Overview","[{\"question\":\"Who is responsible for managing a cybersecurity incident under this plan?\",\"answer\":\"The Incident Response Lead manages the cybersecurity incident or delegates that responsibility to an appropriate person.\"},{\"question\":\"What are the main phases of the incident handling process?\",\"answer\":\"The plan follows Identification, Containment, Eradication, Recovery, and Lessons Learned, including actions taken during and after an incident.\"},{\"question\":\"What information does the plan require collecting during incident data collection?\",\"answer\":\"The plan requires critical incident information to support reporting and sharing with local, state, and federal reporting authorities, law enforcement, and external entities while enabling faster assistance.\"}]","Cybersecurity Incident Response Plan Template - Version X - PLAN INFORMATION | DOCX",1788247414,6,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":14,"keywords":34,"description":15,"schema_data":35,"social_meta":87,"head_meta":89,"extra_data":91,"updated_unix":28},"cybersecurity-incident-response-plan-template-version-x-plan-information","",{"@graph":36,"@context":86},[37,54,69],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":11},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/template/","Template",2,{"item":49,"name":13,"@type":43,"position":50},"https://docshare.wps.com/template/forms/",3,{"item":52,"name":14,"@type":43,"position":53},"https://docshare.wps.com/template/cybersecurity-incident-response-plan-template-version-x-plan-information/169187/",4,{"url":52,"name":14,"@type":55,"author":56,"headline":14,"publisher":58,"fileFormat":61,"inLanguage":23,"description":15,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/vnd.openxmlformats-officedocument.wordprocessingml.document","2026-09-05","2026-09-01",true,{"@type":66,"interactionType":67,"userInteractionCount":29},"InteractionCounter",{"@type":68},"ViewAction",{"@type":70,"mainEntity":71},"FAQPage",[72,78,82],{"name":73,"@type":74,"acceptedAnswer":75},"Who is responsible for managing a cybersecurity incident under this plan?","Question",{"text":76,"@type":77},"The Incident Response Lead manages the cybersecurity incident or delegates that responsibility to an appropriate person.","Answer",{"name":79,"@type":74,"acceptedAnswer":80},"What are the main phases of the incident handling process?",{"text":81,"@type":77},"The plan follows Identification, Containment, Eradication, Recovery, and Lessons Learned, including actions taken during and after an incident.",{"name":83,"@type":74,"acceptedAnswer":84},"What information does the plan require collecting during incident data collection?",{"text":85,"@type":77},"The plan requires critical incident information to support reporting and sharing with local, state, and federal reporting authorities, law enforcement, and external entities while enabling faster assistance.","https://schema.org",{"og:url":52,"og:type":88,"og:title":14,"og:site_name":59,"og:description":15},"article",{"robots":90,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":93},[94,99,104,109,114,118,121,126,131],{"id":95,"doc_module":11,"doc_module_name":46,"category_name":96,"show_sort_weight":97,"slug":98},11,"Presentations",90,"presentations",{"id":100,"doc_module":11,"doc_module_name":46,"category_name":101,"show_sort_weight":102,"slug":103},12,"Resumes",80,"resumes",{"id":105,"doc_module":11,"doc_module_name":46,"category_name":106,"show_sort_weight":107,"slug":108},14,"Invoices",70,"invoices",{"id":110,"doc_module":11,"doc_module_name":46,"category_name":111,"show_sort_weight":112,"slug":113},15,"Posters",60,"posters",{"id":21,"doc_module":11,"doc_module_name":46,"category_name":115,"show_sort_weight":116,"slug":117},"Social Media",50,"social-media",{"id":12,"doc_module":11,"doc_module_name":46,"category_name":13,"show_sort_weight":119,"slug":120},40,"forms",{"id":122,"doc_module":11,"doc_module_name":46,"category_name":123,"show_sort_weight":124,"slug":125},18,"Letters",30,"letters",{"id":127,"doc_module":11,"doc_module_name":46,"category_name":128,"show_sort_weight":129,"slug":130},21,"Paper Templates",5,"papers-templates",{"id":132,"doc_module":11,"doc_module_name":46,"category_name":133,"show_sort_weight":4,"slug":134},158,"General","general-158"]