Skip to main content

Pro audit program · v1.0

Incident Response Plan Quick Check

Is your IR plan more than a PDF? Test for tabletop exercises, RACI, comms templates, escalation paths and lessons-learned.

  • General target area
  • NIST 800-61 framework
  • 7 controls in this program
  • Cyentrix Cyentrix Trusted Author

About this program

Is your IR plan more than a PDF? Test for tabletop exercises, RACI, comms templates, escalation paths and lessons-learned.

Risks addressed

  • Critical Slow, ad-hoc IR extends breach impact
  • High Wrong people contacted (or none) during a real incident
  • High Regulators / customers notified late or inconsistently
  • High Logs purged before forensics can run

Controls (7)

  1. Documented IR plan

    High

    An incident response (IR) plan is a documented, formally adopted procedure that defines roles, responsibilities, communication protocols, escalation paths, and technical steps to detect, contain, eradicate, recover from, and learn from cybersecurity incidents. The plan typically includes contact lists, decision…

    How to test + evidence

    Testing procedure: Confirm an IR plan exists, dated within 12 months, owned + approved.

    Evidence to collect: IR plan PDF.

  2. Roles + RACI defined

    High

    This control requires the organization to document and assign clear roles, responsibilities, accountabilities, and consultation/information requirements (RACI) for cybersecurity functions and activities. The RACI matrix explicitly identifies who is Responsible for execution, who is Accountable for outcomes, who must be…

    How to test + evidence

    Testing procedure: Plan names IR Lead, Comms, Legal, Tech, with contact details.

    Evidence to collect: RACI table in plan.

  3. Tabletop exercise within last 12 months

    High

    A tabletop exercise is a facilitated discussion-based session where stakeholders walk through incident response, business continuity, or disaster recovery scenarios in a controlled, low-pressure environment. The exercise tests the organization's preparedness, validates response procedures, identifies gaps in plans or communication…

    How to test + evidence

    Testing procedure: Last tabletop date + attendees + scenario; lessons-learned actioned.

    Evidence to collect: Tabletop after-action report.

  4. Escalation paths to legal + insurer

    Medium

    This control ensures that incident response procedures include formally documented and tested escalation pathways to both legal counsel and cyber insurance carriers when security incidents meet predefined severity thresholds or involve regulated data. These pathways specify contact information, triggering criteria…

    How to test + evidence

    Testing procedure: Plan documents when/how to engage legal counsel and cyber insurance.

    Evidence to collect: Plan extract.

  5. Comms templates ready

    Medium

    Pre-approved communication templates are prepared, tested, and made readily accessible to incident response and business continuity teams for use during security incidents, data breaches, or operational disruptions. These templates cover internal notifications, external stakeholder communications, regulatory breach notifications, customer advisories,…

    How to test + evidence

    Testing procedure: Pre-approved templates for staff, customers, regulators, media.

    Evidence to collect: Template library.

  6. Forensic readiness — logs + tools

    High

    Forensic readiness for logs and tools ensures that an organization maintains comprehensive, tamper-evident logs and has pre-deployed forensic analysis capabilities to support incident investigation. This control requires centralized log aggregation with adequate retention periods, synchronized time sources, write-once or immutable…

    How to test + evidence

    Testing procedure: Log sources retained >=90 days; forensic tooling on standby (in-house or retainer).

    Evidence to collect: SIEM retention + retainer contract.

  7. Lessons-learned loop

    Medium

    A lessons-learned loop is a structured process for capturing, analyzing, and incorporating insights from security incidents, near-misses, penetration tests, tabletop exercises, and operational failures into the organization's security posture. It typically involves post-incident reviews, root-cause analysis sessions, and formal mechanisms…

    How to test + evidence

    Testing procedure: Closed incidents trigger a post-mortem; actions tracked to completion.

    Evidence to collect: Post-mortem register.