[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-169188-en":3,"doc-seo-169188-105":30,"detail-sidebar-cat-1-en-105":92},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":11,"category_id":12,"category_name":13,"doc_title":14,"doc_description":15,"doc_content":16,"file_id":17,"file_url":18,"file_type":19,"file_size":20,"view_count":11,"is_deleted":4,"is_public":11,"is_downloadable":11,"audit_status":11,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":15,"update_tm":28,"read_time":29},169188,8796095461610,"Oliver","https://ap-avatar.wpscdn.com/davatar_276721f389ce27ea32af1340a28f341c",1,158,"General","Incident Response Plan - Cyber Security - Incident Management","Incident Response Plan defines how cyber-security incidents are governed within existing operational procedures, including secure storage, backup locations, and maintaining a single source of truth. It sets purpose and scope covering all employees and contracted technical parties, and provides communication templates for public and internal audiences. The plan describes incident management roles, the cyber-security incident definition, team membership, declaring triggers, severity levels, identification workflow, and escalation steps for activating the response process.","Incident Response Plan\nDocument Control Information\nRevision History\nThis document is formally reviewed at least annually (including when there are significant changes to the business, when risks are identified, when there are changes to adopted standards or when there are changes in legal regulations that impact. Interim updates will be documented and integrated as required in response to changing business objectives or the risk environment.  Changes will be communicated as broadly as possible through the use of email, company announcements, and other methods as applicable.\nContents\n\u0013 TOC \\o \"1-1\" \\h \\z \\t \"Heading 2,2,Heading 2 PQ,2,Heading 2 None,2,Heading 2 PQ None,2\" \u0014\u0013 HYPERLINK \\l \"_Toc52279770\" \u0014Incident Response Plan\t\u0013 PAGEREF _Toc52279770 \\h \u00141\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc52279771\" \u0014Document Control Information\t\u0013 PAGEREF _Toc52279771 \\h \u00141\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc52279772\" \u0014Revision History\t\u0013 PAGEREF _Toc52279772 \\h \u00141\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc52279773\" \u0014Contents\t\u0013 PAGEREF _Toc52279773 \\h \u00142\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc52279774\" \u0014Purpose\t\u0013 PAGEREF _Toc52279774 \\h \u00143\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc52279775\" \u0014SCOPE\t\u0013 PAGEREF _Toc52279775 \\h \u00143\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc52279776\" \u0014Communication Plan\t\u0013 PAGEREF _Toc52279776 \\h \u00144\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc52279777\" \u0014Incident management\t\u0013 PAGEREF _Toc52279777 \\h \u00145\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc52279778\" \u0014What Is a Cyber Security Incident\t\u0013 PAGEREF _Toc52279778 \\h \u00145\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc52279779\" \u0014Who Is On The Incident Response Team?\t\u0013 PAGEREF _Toc52279779 \\h \u00146\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc52279780\" \u0014Declaring A Cyber-Security Incident\t\u0013 PAGEREF _Toc52279780 \\h \u00146\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc52279781\" \u0014Incident Severity Levels\t\u0013 PAGEREF _Toc52279781 \\h \u00147\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc52279782\" \u0014Identification\t\u0013 PAGEREF _Toc52279782 \\h \u00148\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc52279783\" \u0014Incident Response\t\u0013 PAGEREF _Toc52279783 \\h \u001410\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc52279784\" \u0014Incident Response Team Contact Details\t\u0013 PAGEREF _Toc52279784 \\h \u001413\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc52279785\" \u0014Appendix a\t\u0013 PAGEREF _Toc52279785 \\h \u001414\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc52279786\" \u0014Incident Register\t\u0013 PAGEREF _Toc52279786 \\h \u001414\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc52279787\" \u0014Cyber-Security Initial Assessment Checklist\t\u0013 PAGEREF _Toc52279787 \\h \u001415\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc52279788\" \u0014Cyber-Security Incident Initiation Checklist\t\u0013 PAGEREF _Toc52279788 \\h \u001416\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc52279789\" \u0014Recovery Progress Checklist\t\u0013 PAGEREF _Toc52279789 \\h \u001417\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc52279790\" \u0014Cyber-Security Incident Close Checklist\t\u0013 PAGEREF _Toc52279790 \\h \u001418\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc52279791\" \u0014Definitons\t\u0013 PAGEREF _Toc52279791 \\h \u001419\u0015\u0015\n\u0015\n\u000f\nPurpose\nCyber Security incidents will be managed within, and integrated to, existing operational procedures. This document should be stored in a location that is secure but accessible to all required parties. In addition to this, backup copies should be stored in other locations to ensure its availability. The core storage point should always be treated as the ‘source of truth’ and most updated version.  Ideally, summary sections should be printed and laminated, pinned to office walls similar to fire escape plans.\nScope\nThe scope of this procedure includes:\nAll employees\nAll Contractors and Consultants working on our software\nAssessment of any software purchased for use in\n\u000f\nCommunication Plan\nResponsibilities\nPublic Communication Template\nPublic Communication Channels\nInternal Communication Template\nInternal Communication Channels\n\u000f\nIncident management\nWhat Is a Cyber Security Incident\nCyber-security incidents are those in the following categories:\n\u000f\nWho Is On The Incident Response Team?\nThe Cybersecurity Incident Response Team consists of the following members:\nCOO\nPMO Manager\nTechnical Lead\nData Quality Manager\nDevOps Manager\nDeclaring A Cyber-Security Incident\nAny of the following team members can declare an Incident/vulnerability:\n\u000f\nIncident Severity Levels\nThe following table illustrates common Severity Levels for Cyber-security incidents:\n\u000f\nIdentification\nA potential cybersecuri","cbCaiguBo5VSOOjh","https://ap.wps.com/l/cbCaiguBo5VSOOjh","docx",957431,20,"English","en",105,"# Purpose\n# SCOPE\n# Communication Plan\n## Responsibilities\n## Public Communication\n## Internal Communication\n# Incident management\n## What Is a Cyber Security Incident\n## Who Is On The Incident Response Team?\n## Declaring A Cyber-Security Incident\n## Incident Severity Levels\n## Identification\n## Incident Response\n# Appendix\n## Incident Register\n## Initial Assessment Checklist\n## Incident Initiation Checklist\n## Recovery Progress Checklist\n## Incident Close Checklist\n## Definitons","[{\"question\":\"What is the document’s purpose and how should it be stored?\",\"answer\":\"Cyber-security incidents are managed through existing operational procedures. The plan must be stored securely but accessible to required parties, with backup copies elsewhere, and the latest version treated as the source of truth.\"},{\"question\":\"Who can declare a cyber-security incident and what happens next?\",\"answer\":\"Members of the incident response team can declare an incident or vulnerability. After declaration or initial assessment, the COO or DevOps Manager activates the plan based on factors such as severity and potential impact.\"},{\"question\":\"How are cyber-security incidents identified and triaged?\",\"answer\":\"Incidents may be identified from multiple sources and require an initial evaluation to determine whether they qualify to activate the plan. The first priority is physical safety and isolating the environment if there is risk of further spread.\"}]","Incident Response Plan - Cyber Security - Incident Management | DOCX",1788247447,7,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":14,"keywords":34,"description":15,"schema_data":35,"social_meta":87,"head_meta":89,"extra_data":91,"updated_unix":28},"incident-response-plan-cyber-security-incident-management","",{"@graph":36,"@context":86},[37,54,69],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":11},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/template/","Template",2,{"item":49,"name":13,"@type":43,"position":50},"https://docshare.wps.com/template/general/",3,{"item":52,"name":14,"@type":43,"position":53},"https://docshare.wps.com/template/incident-response-plan-cyber-security-incident-management/169188/",4,{"url":52,"name":14,"@type":55,"author":56,"headline":14,"publisher":58,"fileFormat":61,"inLanguage":23,"description":15,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/vnd.openxmlformats-officedocument.wordprocessingml.document","2026-09-05","2026-09-01",true,{"@type":66,"interactionType":67,"userInteractionCount":53},"InteractionCounter",{"@type":68},"ViewAction",{"@type":70,"mainEntity":71},"FAQPage",[72,78,82],{"name":73,"@type":74,"acceptedAnswer":75},"What is the document’s purpose and how should it be stored?","Question",{"text":76,"@type":77},"Cyber-security incidents are managed through existing operational procedures. The plan must be stored securely but accessible to required parties, with backup copies elsewhere, and the latest version treated as the source of truth.","Answer",{"name":79,"@type":74,"acceptedAnswer":80},"Who can declare a cyber-security incident and what happens next?",{"text":81,"@type":77},"Members of the incident response team can declare an incident or vulnerability. After declaration or initial assessment, the COO or DevOps Manager activates the plan based on factors such as severity and potential impact.",{"name":83,"@type":74,"acceptedAnswer":84},"How are cyber-security incidents identified and triaged?",{"text":85,"@type":77},"Incidents may be identified from multiple sources and require an initial evaluation to determine whether they qualify to activate the plan. The first priority is physical safety and isolating the environment if there is risk of further spread.","https://schema.org",{"og:url":52,"og:type":88,"og:title":14,"og:site_name":59,"og:description":15},"article",{"robots":90,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":93},[94,99,104,109,114,119,124,129,134],{"id":95,"doc_module":11,"doc_module_name":46,"category_name":96,"show_sort_weight":97,"slug":98},11,"Presentations",90,"presentations",{"id":100,"doc_module":11,"doc_module_name":46,"category_name":101,"show_sort_weight":102,"slug":103},12,"Resumes",80,"resumes",{"id":105,"doc_module":11,"doc_module_name":46,"category_name":106,"show_sort_weight":107,"slug":108},14,"Invoices",70,"invoices",{"id":110,"doc_module":11,"doc_module_name":46,"category_name":111,"show_sort_weight":112,"slug":113},15,"Posters",60,"posters",{"id":115,"doc_module":11,"doc_module_name":46,"category_name":116,"show_sort_weight":117,"slug":118},16,"Social Media",50,"social-media",{"id":120,"doc_module":11,"doc_module_name":46,"category_name":121,"show_sort_weight":122,"slug":123},17,"Forms",40,"forms",{"id":125,"doc_module":11,"doc_module_name":46,"category_name":126,"show_sort_weight":127,"slug":128},18,"Letters",30,"letters",{"id":130,"doc_module":11,"doc_module_name":46,"category_name":131,"show_sort_weight":132,"slug":133},21,"Paper Templates",5,"papers-templates",{"id":12,"doc_module":11,"doc_module_name":46,"category_name":13,"show_sort_weight":4,"slug":135},"general-158"]