A. Develop an incident response plan that: 1. provides the organization with a roadmap for implementing its incident response capability 2. describes the structure and organization of the incident response capability 3. provides a high-level approach for how the incident response capability fits into the overall organization 4. defines reportable incidents 5. addresses the sharing of incident information 6. designates responsibilities to organizational entities, personnel, or roles. B. Distribute copies of the incident response plan to designated incident response personnel (identified by name and/or by role) and organizational elements. C. Update the incident response plan to address system and organizational changes or problems encountered during plan implementation, execution, or testing. D. Protect the incident response plan from unauthorized disclosure.
Source: Canadian Centre for Cyber Security ITSP.10.171 (2025), adapted from NIST SP 800-171 Rev. 3
In Plain English
You need a formal, written incident response plan that defines how your organization handles security incidents. It must cover the team structure, roles, what constitutes a reportable incident, how information is shared, how effectiveness is measured, and what resources are needed. The plan must be distributed to relevant personnel, updated after changes or exercises, and protected from unauthorized access.
These are typical controls and implementation steps. Your systems and environment may differ.
Typical Control Documented incident response plan
Implementation Steps
Develop a comprehensive incident response plan covering organizational structure, roles, reportable incident definitions, information sharing protocols, metrics, and resource requirements
Store the plan in a controlled document repository with version control and access restricted to authorized personnel
Distribute the plan to all designated incident response personnel and relevant organizational elements; track distribution and acknowledgement
Review and update the plan at least annually and after any significant incident, exercise, or organizational change; communicate updates to all plan holders
Tools / Systems
Document management system (Confluence, SharePoint, Google Docs with access controls)Version control for plan documentDistribution and acknowledgement tracking (GRC platform, email receipts)Plan review and update tracking
Typical Control Documented incident response plan
Evidence Artifacts
Current incident response plan with version history and management approval
Distribution records showing plan delivery to all designated personnel
Update log showing plan revisions following incidents, exercises, or changes
📅Annual review and approval; per-event updates; annual distribution verification
Cross-framework mappings coming in v1.1
When we add ISO 42001 and ISO 27001, you'll see which controls map to this criterion.
ISO
ISO 42001
AI Management Systems
ISO
ISO 27001
Information Security
Mapping data will appear here automatically when the frameworks are published.
03.07.04
Maintenance tools
Maintenance
3 evidence1 control
03.07.05
Non-local maintenance
Maintenance
3 evidence1 control
03.07.06
Maintenance personnel
Maintenance
4 evidence1 control
03.08.01
Media storage
Media protection
3 evidence1 control
03.08.02
Media access
Media protection
3 evidence1 control
03.08.03
Media sanitization
Media protection
3 evidence1 control
03.08.04
Media marking
Media protection
3 evidence1 control
03.08.05
Media transport
Media protection
3 evidence1 control
03.08.07
Media use
Media protection
3 evidence1 control
03.08.09
System backup - cryptographic protection
Media protection
3 evidence1 control
03.09.01
Personnel screening
Personnel security
3 evidence1 control
03.09.02
Personnel termination and transfer
Personnel security
3 evidence1 control
03.10.01
Physical access authorizations
Physical protection
3 evidence1 control
03.10.02
Monitoring physical access
Physical protection
3 evidence1 control
03.10.06
Alternate work site
Physical protection
3 evidence1 control
03.10.07
Physical access control
Physical protection
3 evidence1 control
03.10.08
Access control for transmission
Physical protection
3 evidence1 control
03.11.01
Risk assessment
Risk assessment
3 evidence1 control
03.11.02
Vulnerability monitoring and scanning
Risk assessment
3 evidence1 control
03.11.04
Risk response
Risk assessment
3 evidence1 control
03.12.01
Security assessment
Security assessment and monitoring
3 evidence1 control
03.12.02
Plan of action and milestones
Security assessment and monitoring
3 evidence1 control
03.12.03
Continuous monitoring
Security assessment and monitoring
3 evidence1 control
03.12.05
Information exchange
Security assessment and monitoring
3 evidence1 control
03.13.01
Boundary protection
System and communications protection
3 evidence1 control
03.13.04
Information in shared system resources
System and communications protection
3 evidence1 control
03.13.06
Network communications - deny by default - allow by exception
System and communications protection
3 evidence1 control
03.13.08
Transmission and storage confidentiality
System and communications protection
3 evidence1 control
03.13.09
Network disconnect
System and communications protection
3 evidence1 control
03.13.10
Cryptographic key establishment and management
System and communications protection
3 evidence1 control
03.13.11
Cryptographic protection
System and communications protection
3 evidence1 control
03.13.12
Collaborative computing devices and applications
System and communications protection
3 evidence1 control
03.13.13
Mobile code
System and communications protection
3 evidence1 control
03.13.15
Session authenticity
System and communications protection
3 evidence1 control
03.14.01
Flaw remediation
System and information integrity
3 evidence1 control
03.14.02
Malicious code protection
System and information integrity
3 evidence1 control
03.14.03
Security alerts, advisories, and directives
System and information integrity
3 evidence1 control
03.14.06
System monitoring
System and information integrity
3 evidence1 control
03.14.08
Information management and retention
System and information integrity
3 evidence1 control
03.14.09
Dedicated administration workstation
System and information integrity
3 evidence1 control
03.15.01
Policy and procedures
Planning
3 evidence1 control
03.15.02
System security plan
Planning
3 evidence1 control
03.15.03
Rules of behaviour
Planning
3 evidence1 control
03.16.01
Security engineering principles
System and services acquisition
3 evidence1 control
03.16.02
Unsupported system components
System and services acquisition
3 evidence1 control
03.16.03
External system services
System and services acquisition
3 evidence1 control
03.17.01
Supply chain risk management plan
Supply chain risk management
3 evidence1 control
03.17.02
Acquisition strategies, tools, and methods
Supply chain risk management
3 evidence1 control
03.17.03
Supply chain requirements and processes
Supply chain risk management
3 evidence1 control
Help us build what matters.
Vote for the next framework, subscribe for updates, and let us know if you'd contribute.
What should we add next?
Vote for the framework you need most.
0
ISO 42001
0
ISO 27001
0
CMMC
0
CPCSC
Stay Updated
Get notified when new frameworks and features are added.
On-premises implementation and evidence
Documented incident response plan
Implementation steps
Draft an incident response plan addressing all required elements: structure, roles, reportable incidents, information sharing, metrics, and resources
Obtain management approval and sign-off on the plan; classify the plan as restricted to prevent unauthorized disclosure
Distribute the plan to all IR team members and relevant departments (IT, legal, HR, communications); collect signed acknowledgements
Update the plan after tests, real incidents, or organizational changes; redistribute and track updated acknowledgements