Incident Response Plan
Detects incident response plans containing containment procedures and escalation matrices.
- Type
- regex
- Confidence
- medium
- Confidence justification
- Medium confidence: keyword-based detection requires corroborative evidence for accurate identification.
- Jurisdictions
- global
- Regulations
- SOCI Act 2018 (Cth), TIA Act 1979 (Cth)
- Frameworks
- CIS Controls, DISP, ISO 27001, NIST CSF, SOC 2
- Data categories
- security, technology
- Scope
- narrow
- Risk rating
- 8
Should match
Incident response plan— Low-tier probe - plan title without response proceduresIncident response plan: containment, eradication, and forensic analysis.— Medium-tier probe - substantive response lifecycle without escalation routingSecurity incident response plan: containment and forensic investigation with severity level and on-call escalation path.— High-tier probe - response lifecycle plus severity and escalation evidence
Should not match
Incident report for workplace injury— Workplace-safety siblingTraffic incident on the highway— Traffic-incident proseThe public cyber guide links to an incident response plan.— Public guidance mentions only the document titleTemplate example: incident response plan with containment, forensic analysis, severity level, and escalation path.— Template contains otherwise high-tier evidence
Known false positives
- Generic incident references in non-cyber contexts. Mitigation: Require cyber-specific terms like IRP, containment, or incident commander.