Home / Fast Track / Incident response & breach reporting
Shared control area · counts toward 10 standards
Incident response & breach reporting
This control area establishes a structured process for detecting, responding to, and recovering from security incidents. Frameworks require it because the ability to minimize damage and notify stakeholders during a breach is critical to operational resilience and legal compliance.
Counts toward
Implement it once
- A written Incident Response Plan (IRP) detailing roles, responsibilities, and communication channels.
- A severity matrix that categorizes incidents (e.g., Low to Critical) based on business impact.
- Monitoring tools or processes for the timely detection of security events.
- Defined containment and eradication procedures tailored to common threat scenarios.
- A breach notification policy specifying which regulators and customers must be notified and within what timeframes.
- An annual testing schedule, such as tabletop exercises, to validate the plan's effectiveness.
Evidence it produces
- The finalized Incident Response Plan and associated policies.
- Incident logs or tickets documenting the lifecycle of detected events from discovery to closure.
- Post-incident reports (Root Cause Analysis) for major security events.
- Documentation of tabletop exercises, including attendee lists and "lessons learned" summaries.
- Communication records proving timely notification to required parties during a breach event.
Where it counts
Most security certifications require proof that an organization handles threats systematically rather than ad hoc. By maintaining one robust IR process, the same documentation and logs serve as evidence for diverse regulatory, legal, and industry-specific audits.