[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-seo-240391-105":3,"detail-sidebar-cat-1-en-105":81,"doc-detail-240391-en":126},{"code":4,"msg":5,"data":6},0,"ok",{"site_id":7,"language":8,"slug":9,"title":10,"keywords":11,"description":12,"schema_data":13,"social_meta":74,"head_meta":76,"extra_data":78,"updated_unix":80},105,"en","incident-response-plan-purpose-scope-roles-and-definitions","Incident Response Plan - Purpose, Scope, Roles and Definitions","","Incident Response Plan sets out how ORG safeguards digital assets, sensitive information, and operational continuity when security threats occur. It defines goals for rapid threat mitigation, restoring operations through predefined procedures, meeting incident reporting and management requirements, and ensuring coordinated action via assigned roles, responsibilities, and communication channels. The scope covers all Incident Response Team members and clarifies that all staff must report suspected issues and follow guidance through the Technology Acceptable Use Policy.",{"@graph":14,"@context":73},[15,34,56],{"@type":16,"itemListElement":17},"BreadcrumbList",[18,23,27,31],{"item":19,"name":20,"@type":21,"position":22},"https://docshare.wps.com","Home","ListItem",1,{"item":24,"name":25,"@type":21,"position":26},"https://docshare.wps.com/template/","Template",2,{"item":28,"name":29,"@type":21,"position":30},"https://docshare.wps.com/template/general/","General",3,{"item":32,"name":10,"@type":21,"position":33},"https://docshare.wps.com/template/incident-response-plan-purpose-scope-roles-and-definitions/240391/",4,{"url":32,"name":10,"@type":35,"image":36,"author":41,"headline":10,"publisher":44,"fileFormat":47,"inLanguage":8,"description":12,"dateModified":48,"datePublished":49,"encodingFormat":47,"isAccessibleForFree":50,"interactionStatistic":51},"DigitalDocument",{"url":37,"@type":38,"width":39,"height":40},"https://docshare.wps.com/thumbnails/incident-response-plan-purpose-scope-roles-and-definitions/240391.png","ImageObject",442,249,{"name":42,"@type":43},"Chumphorn","Person",{"url":19,"name":45,"@type":46},"DocShare","Organization","application/pdf","2026-09-26","2026-09-11",true,{"@type":52,"interactionType":53,"userInteractionCount":55},"InteractionCounter",{"@type":54},"ViewAction",5,{"@type":57,"mainEntity":58},"FAQPage",[59,65,69],{"name":60,"@type":61,"acceptedAnswer":62},"What is the purpose of the Incident Response Plan at ORG?","Question",{"text":63,"@type":64},"It enables rapid identification, containment, and neutralization of security incidents, supports quicker restoration of normal operations, and helps meet legal and industry incident reporting requirements. It also ensures coordinated action through clearly defined roles and communication channels.","Answer",{"name":66,"@type":61,"acceptedAnswer":67},"Who does the Incident Response Plan apply to?",{"text":68,"@type":64},"The plan is designed for and applies to all members of the Incident Response Team. It also states that all staff have a role in security by reporting suspected incidents through the Technology Acceptable Use Policy.",{"name":70,"@type":61,"acceptedAnswer":71},"How does ORG handle incidents after detection?",{"text":72,"@type":64},"After identifying a vulnerability or incident, ORG takes actions based on the assigned severity level. For confirmed breaches, it executes a predefined procedure, including notifying affected individuals and partners as necessary.","https://schema.org",{"og:url":32,"og:type":75,"og:title":10,"og:site_name":45,"og:description":12},"article",{"robots":77,"canonical":32},"index,follow",{"doc_id":79,"site_id":7},240391,1789160895,{"code":4,"msg":82,"data":83},"success",[84,89,94,99,104,109,114,119,123],{"id":85,"doc_module":22,"doc_module_name":25,"category_name":86,"show_sort_weight":87,"slug":88},11,"Presentations",90,"presentations",{"id":90,"doc_module":22,"doc_module_name":25,"category_name":91,"show_sort_weight":92,"slug":93},12,"Resumes",80,"resumes",{"id":95,"doc_module":22,"doc_module_name":25,"category_name":96,"show_sort_weight":97,"slug":98},14,"Invoices",70,"invoices",{"id":100,"doc_module":22,"doc_module_name":25,"category_name":101,"show_sort_weight":102,"slug":103},15,"Posters",60,"posters",{"id":105,"doc_module":22,"doc_module_name":25,"category_name":106,"show_sort_weight":107,"slug":108},16,"Social Media",50,"social-media",{"id":110,"doc_module":22,"doc_module_name":25,"category_name":111,"show_sort_weight":112,"slug":113},17,"Forms",40,"forms",{"id":115,"doc_module":22,"doc_module_name":25,"category_name":116,"show_sort_weight":117,"slug":118},18,"Letters",30,"letters",{"id":120,"doc_module":22,"doc_module_name":25,"category_name":121,"show_sort_weight":55,"slug":122},21,"Paper Templates","papers-templates",{"id":124,"doc_module":22,"doc_module_name":25,"category_name":29,"show_sort_weight":4,"slug":125},158,"general-158",{"code":4,"msg":82,"data":127},{"doc_id":79,"user_id":128,"nickname":42,"user_avatar":129,"doc_module":22,"category_id":124,"category_name":29,"doc_title":10,"doc_description":12,"doc_content":130,"file_id":131,"file_url":132,"file_type":133,"file_size":134,"view_count":55,"is_deleted":4,"is_public":22,"is_downloadable":22,"audit_status":22,"page_count":85,"language":135,"language_code":8,"site_id":7,"html_lang":8,"table_of_contents":136,"faqs":137,"seo_title":138,"seo_description":12,"update_tm":80,"read_time":33},2336475401981,"https://ap-avatar.wpscdn.com/avatar/22000c94efd8d5204d?x-image-process=image/resize,m_fixed,w_180,h_180&k=1786935347598174694","Incident Response Plan  \nPurpose  \nORG maintains an Incident Response Plan to safeguard our digital assets, protect sensitive information, and maintain operational continuity in the face of potential security threats. This plan serves several critical purposes:  \n1. Rapid Threat Mitigation: It enables us to quickly identify, contain, and neutralize security incidents, minimizing potential damage and data loss.  \n2. Operational Resilience: By having predetermined procedures in place, we can swiftly restore normal operations, reducing downtime and associated costs.  \n3. Regulatory Compliance: The plan helps us meet legal and industry-speciﬁc requirements for incident reporting and management.  \n4. Coordinated Action: The plan deﬁnes roles, responsibilities, and communication channels, ensuring a cohesive response across our ORG.  \nBy maintaining and regularly updating this Incident Response Plan, ORG strengthens its overall security posture, protects its reputation, and ensures its ability to deliver uninterrupted service to our constituents and stakeholders.  \nScope  \nThis Incident Response Plan policy is designed speciﬁcally for and applies to all members of the Incident Response Team. It outlines comprehensive guidelines for team members, detailing the process for implementing a response to potential security breaches. To ensure its effectiveness, the policy will be made readily accessible to all Incident Response Team members at all times.  \nWhile the primary focus of this policy is on the Incident Response Team, it's important to note that all staff at [ORG] play a role in maintaining security. As such, all employees will receive guidance on reporting suspected incidents through the Technology Acceptable Use Policy, which they will be required to review and sign. This approach ensures a cohesive and ORG-wide commitment to incident response and security awareness.  \nBackground  \nThe primary objective of [ORG]'s Information Security Program is to detect and address security vulnerabilities proactively, thereby preventing incidents and breaches. [ORG] places a high priority on safeguarding its network and data against unauthorized actions that could compromise its operations and mission.  \nRecognizing that incidents may still occur despite preventive measures,[ORG] is committed to a swift and effective response process. This process encompasses detection, containment, investigation, and resolution, followed by comprehensive communication with all relevant stakeholders.  \nAll users within [ORG] are required to report any observed or suspected security issues promptly, as detailed in this document. To enhance the detection of vulnerabilities and incidents,[ORG] utilizes automated tools for scanning and monitoring its systems and networks.  \nUpon identifying a vulnerability or incident,[ORG] will take appropriate actions based on the assigned severity level. In the event of a conﬁrmed breach,[ORG] will execute apredeﬁned procedure to address and resolve the situation, including notifying affected individuals and partners as necessary.  \nThis Incident Response Plan outlines the framework for managing these processes, ensuring [ORG] can respond effectively to security threats while minimizing potential impacts on its operations and stakeholders.  \nThis document also clariﬁes terms and deﬁnitions relevant to [ORG]'s incident response efforts.  \nWithin this document, the following deﬁnitions apply:  \nInformation Security Vulnerability:  \nA vulnerability in an information system, information system security procedures, or administrative controls that could be exploited to gain unauthorized access to information or to disrupt critical processing.  \nInformation Security Incident:  \nA suspected, attempted, successful, or imminent threat of unauthorized access, use, disclosure, breach, modiﬁcation, or destruction of information; interference with information technology operations; or signiﬁcant violation of information security policy.  \n","cbCaiqcy4YzOfqz1","https://ap.wps.com/l/cbCaiqcy4YzOfqz1","pdf",183954,"English","# Purpose\n## Scope\n## Background\n## Definitions\n## Roles and Responsibilities","[{\"question\":\"What is the purpose of the Incident Response Plan at ORG?\",\"answer\":\"It enables rapid identification, containment, and neutralization of security incidents, supports quicker restoration of normal operations, and helps meet legal and industry incident reporting requirements. It also ensures coordinated action through clearly defined roles and communication channels.\"},{\"question\":\"Who does the Incident Response Plan apply to?\",\"answer\":\"The plan is designed for and applies to all members of the Incident Response Team. It also states that all staff have a role in security by reporting suspected incidents through the Technology Acceptable Use Policy.\"},{\"question\":\"How does ORG handle incidents after detection?\",\"answer\":\"After identifying a vulnerability or incident, ORG takes actions based on the assigned severity level. For confirmed breaches, it executes a predefined procedure, including notifying affected individuals and partners as necessary.\"}]","Incident Response Plan - Purpose, Scope, Roles and Definitions | PDF"]