[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-169189-en":3,"doc-seo-169189-105":30,"detail-sidebar-cat-1-en-105":92},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":11,"category_id":12,"category_name":13,"doc_title":14,"doc_description":15,"doc_content":16,"file_id":17,"file_url":18,"file_type":19,"file_size":20,"view_count":4,"is_deleted":4,"is_public":11,"is_downloadable":11,"audit_status":11,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":15,"update_tm":28,"read_time":29},169189,1099514068035,"Ezra","https://ap-avatar.wpscdn.com/davatar_276721f389ce27ea32af1340a28f341c",1,158,"General","Incident Response Plan - Purpose","Incident Response Plan provides direction and focus for handling information security incidents that adversely affect the organization’s information resources. The plan is owned by the Organization Executive Team and aligns its processes and terminology with NIST incident response documentation and the National Incident Management System (NIMS). It clarifies when and how to engage NIMS, including during regional or national incidents requiring multi-agency coordination, supported by staff training across key NIMS areas.","Name of Organization\nIncident Response Plan\nDecember 2021\nRevision History\nInstructions\nThe (Name of Organization) Incident Response Plan is designated For Official Use Only (FOUO) and is the property of (Name of Organization). Only (Name of Organization) representatives may distribute the handbook to individuals on a need-to-know basis. Distribution by other individuals without prior authorization is prohibited. This document is unclassified but contains sensitive information.\n\u0003Table of Contents\n\u0013 TOC \\o \"1-3\" \\h \\z \\u \u0014\u0013 HYPERLINK \\l \"_Toc89329870\" \u0014I.\tPurpose\t\u0013 PAGEREF _Toc89329870 \\h \u00146\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc89329871\" \u0014II.\tMission\t\u0013 PAGEREF _Toc89329871 \\h \u00146\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc89329872\" \u0014III.\tScope\t\u0013 PAGEREF _Toc89329872 \\h \u00147\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc89329873\" \u0014IV.\tIncident Response High Level Process\t\u0013 PAGEREF _Toc89329873 \\h \u00148\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc89329874\" \u0014V.\tConfidentiality\t\u0013 PAGEREF _Toc89329874 \\h \u00149\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc89329875\" \u0014VI.\tReport Management\t\u0013 PAGEREF _Toc89329875 \\h \u00149\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc89329876\" \u0014Cyber Security Incident Log\t\u0013 PAGEREF _Toc89329876 \\h \u00149\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc89329877\" \u0014Incident Summary Report (ISR)\t\u0013 PAGEREF _Toc89329877 \\h \u00149\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc89329878\" \u0014Process Improvement Plan (PIP)\t\u0013 PAGEREF _Toc89329878 \\h \u001410\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc89329879\" \u0014VII.\tResource Planning\t\u0013 PAGEREF _Toc89329879 \\h \u001410\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc89329880\" \u0014VIII.\tRoles and Responsibilities\t\u0013 PAGEREF _Toc89329880 \\h \u001410\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc89329881\" \u0014Incident Commander\t\u0013 PAGEREF _Toc89329881 \\h \u001411\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc89329882\" \u0014Chief Security Information/Technology Officer (CISO/CIO/CTO)\t\u0013 PAGEREF _Toc89329882 \\h \u001411\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc89329883\" \u0014Incident Handling Team (IHT)\t\u0013 PAGEREF _Toc89329883 \\h \u001412\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc89329884\" \u0014Cybersecurity Incident Response Team (CIRT)\t\u0013 PAGEREF _Toc89329884 \\h \u001412\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc89329885\" \u0014Incident Response Team Members\t\u0013 PAGEREF _Toc89329885 \\h \u001412\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc89329886\" \u0014Cost Unit Leader\t\u0013 PAGEREF _Toc89329886 \\h \u001413\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc89329887\" \u0014Documentation Unit Leader\t\u0013 PAGEREF _Toc89329887 \\h \u001413\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc89329888\" \u0014Support Teams\t\u0013 PAGEREF _Toc89329888 \\h \u001414\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc89329889\" \u0014IX.\tIncident Response Life Cycle\t\u0013 PAGEREF _Toc89329889 \\h \u001417\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc89329890\" \u0014Preparation\t\u0013 PAGEREF _Toc89329890 \\h \u001417\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc89329891\" \u0014Preventing Incidents\t\u0013 PAGEREF _Toc89329891 \\h \u001417\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc89329892\" \u0014Detection and Analysis\t\u0013 PAGEREF _Toc89329892 \\h \u001418\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc89329893\" \u0014Signs of an Incident\t\u0013 PAGEREF _Toc89329893 \\h \u001418\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc89329894\" \u0014Sources of Precursors and Indications\t\u0013 PAGEREF _Toc89329894 \\h \u001418\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc89329895\" \u0014Incident Analysis\t\u0013 PAGEREF _Toc89329895 \\h \u001418\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc89329896\" \u0014Incident Documentation\t\u0013 PAGEREF _Toc89329896 \\h \u001419\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc89329897\" \u0014Incident Prioritization\t\u0013 PAGEREF _Toc89329897 \\h \u001419\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc89329898\" \u0014Containment, Eradication, and Recovery\t\u0013 PAGEREF _Toc89329898 \\h \u001420\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc89329899\" \u0014Choosing a Containment Strategy\t\u0013 PAGEREF _Toc89329899 \\h \u001420\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc89329900\" \u0014Evidence Gathering and Handling\t\u0013 PAGEREF _Toc89329900 \\h \u001420\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc89329901\" \u0014Forensics for standard computers\t\u0013 PAGEREF _Toc89329901 \\h \u001420\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc89329902\" \u0014Forensics for mobile devices\t\u0013 PAGEREF _Toc89329902 \\h \u001420\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc89329903\" \u0014Identifying the Attacker\t\u0013 PAGEREF _Toc89329903 \\h \u001420\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc89329904\" \u0014Eradication and Recovery\t\u0013 PAGEREF _Toc89329904 \\h \u001421\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc89329905\" \u0014Post-Incident Activity\t\u0013 PAGEREF _Toc89329905 \\h \u001421\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc89329906\" \u0014Lessons Learned\t\u0013 PAGEREF _Toc89329906 \\h \u001421\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc89329907\" \u0014Using Collected Incident Data\t\u0013 PAGEREF _Toc89329907 \\h \u001421\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc89329908\" \u0014Evidence Retention\t\u0013 PAGEREF _Toc89329908 \\h \u001422\u0015\u0015\n\u0013 HYPE","cbCaid7QDT51Hrn2","https://ap.wps.com/l/cbCaid7QDT51Hrn2","docx",318743,31,"English","en",105,"# Purpose\n## Alignment with NIST Incident Response and NIMS\n## Engagement triggers for regional and national incidents\n## Recommended NIMS training areas\n## Resource Management\n## Command and Coordination\n## Communications and Information Management\n## Incident Command System","[{\"question\":\"Who owns and directs the Incident Response Plan?\",\"answer\":\"The plan is owned by the Organization Executive Team and provides direction for incident handling.\"},{\"question\":\"What standards are used to align the plan’s processes and terminology?\",\"answer\":\"Processes and nomenclature are aligned with NIST Incident Response documentation and the National Incident Management System (NIMS).\"},{\"question\":\"When does the plan recommend engaging NIMS and what capabilities should staff have?\",\"answer\":\"Engage NIMS when incidents are regional or national and require collaboration across multiple agencies; maintain staff trained in key NIMS areas such as resource management, command and coordination, communications and information management, and the Incident Command System.\"}]","Incident Response Plan - Purpose | DOCX",1788247457,11,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":14,"keywords":34,"description":15,"schema_data":35,"social_meta":87,"head_meta":89,"extra_data":91,"updated_unix":28},"incident-response-plan-purpose","",{"@graph":36,"@context":86},[37,54,69],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":11},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/template/","Template",2,{"item":49,"name":13,"@type":43,"position":50},"https://docshare.wps.com/template/general/",3,{"item":52,"name":14,"@type":43,"position":53},"https://docshare.wps.com/template/incident-response-plan-purpose/169189/",4,{"url":52,"name":14,"@type":55,"author":56,"headline":14,"publisher":58,"fileFormat":61,"inLanguage":23,"description":15,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/vnd.openxmlformats-officedocument.wordprocessingml.document","2026-09-03","2026-09-01",true,{"@type":66,"interactionType":67,"userInteractionCount":47},"InteractionCounter",{"@type":68},"ViewAction",{"@type":70,"mainEntity":71},"FAQPage",[72,78,82],{"name":73,"@type":74,"acceptedAnswer":75},"Who owns and directs the Incident Response Plan?","Question",{"text":76,"@type":77},"The plan is owned by the Organization Executive Team and provides direction for incident handling.","Answer",{"name":79,"@type":74,"acceptedAnswer":80},"What standards are used to align the plan’s processes and terminology?",{"text":81,"@type":77},"Processes and nomenclature are aligned with NIST Incident Response documentation and the National Incident Management System (NIMS).",{"name":83,"@type":74,"acceptedAnswer":84},"When does the plan recommend engaging NIMS and what capabilities should staff have?",{"text":85,"@type":77},"Engage NIMS when incidents are regional or national and require collaboration across multiple agencies; maintain staff trained in key NIMS areas such as resource management, command and coordination, communications and information management, and the Incident Command System.","https://schema.org",{"og:url":52,"og:type":88,"og:title":14,"og:site_name":59,"og:description":15},"article",{"robots":90,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":93},[94,98,103,108,113,118,123,128,133],{"id":29,"doc_module":11,"doc_module_name":46,"category_name":95,"show_sort_weight":96,"slug":97},"Presentations",90,"presentations",{"id":99,"doc_module":11,"doc_module_name":46,"category_name":100,"show_sort_weight":101,"slug":102},12,"Resumes",80,"resumes",{"id":104,"doc_module":11,"doc_module_name":46,"category_name":105,"show_sort_weight":106,"slug":107},14,"Invoices",70,"invoices",{"id":109,"doc_module":11,"doc_module_name":46,"category_name":110,"show_sort_weight":111,"slug":112},15,"Posters",60,"posters",{"id":114,"doc_module":11,"doc_module_name":46,"category_name":115,"show_sort_weight":116,"slug":117},16,"Social Media",50,"social-media",{"id":119,"doc_module":11,"doc_module_name":46,"category_name":120,"show_sort_weight":121,"slug":122},17,"Forms",40,"forms",{"id":124,"doc_module":11,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},18,"Letters",30,"letters",{"id":129,"doc_module":11,"doc_module_name":46,"category_name":130,"show_sort_weight":131,"slug":132},21,"Paper Templates",5,"papers-templates",{"id":12,"doc_module":11,"doc_module_name":46,"category_name":13,"show_sort_weight":4,"slug":134},"general-158"]