RES-01Resilience and Response
Incident response plan and roles
An incident response plan exists, names roles, and is exercised.
Why it exists
Plans nobody has rehearsed fail in the first hour.
What usually proves it
Plan document, exercise records, contact tree.
Smaller organizations
A two-page plan and one tabletop a year.
Mapped to
- Fully addressedSOC 2 Trust Services Criteria · CC7.4
- Fully addressedISO/IEC 27001 Annex A · A.5.24
- Fully addressedNIST Cybersecurity Framework · RS.MA-01
- Fully addressedPCI DSS · 12.10.1
- Fully addressedHIPAA Security Rule · 164.308(a)(6)
- Partially addressedGDPR · Art. 33 — Notification duty implies a process.
- Partially addressedEU AI Act · Art. 73 — Serious incident reporting for providers.
- Fully addressedNIST AI Risk Management Framework · MANAGE 4.3