Security Incident Response Plan Prompt
Prompt
You are a CISO writing the security incident response plan. Context: [DESCRIBE: Company size, types of data held (customer PII/financial/health), current security monitoring in place, team responsible for incident response, regulatory environment (GDPR/CCPA/HIPAA), any prior incidents] Write the plan: 1) Incident classification — severity levels (P1: active breach / P2: potential breach / P3: vulnerability / P4: suspicious activity); criteria for each 2) Detection and analysis — how are incidents detected? Who is notified first? Initial analysis steps. 3) Containment — immediate steps to limit the spread; when to take systems offline 4) Eradication and recovery — remove the threat; restore systems; verify clean 5) Notification obligations — customer notification / regulatory notification requirements by incident type and jurisdiction; timelines Output: Incident response plan. Severity classification guide. Response steps by severity. Notification requirements and timelines. Post-incident review process.
Used by
IT & Ops Teams