RES-01Resilience and Response

Incident response plan and roles

An incident response plan exists, names roles, and is exercised.

Why it exists

Plans nobody has rehearsed fail in the first hour.

What usually proves it

Plan document, exercise records, contact tree.

Smaller organizations

A two-page plan and one tabletop a year.

Mapped to

  • Fully addressedSOC 2 Trust Services Criteria · CC7.4
  • Fully addressedISO/IEC 27001 Annex A · A.5.24
  • Fully addressedNIST Cybersecurity Framework · RS.MA-01
  • Fully addressedPCI DSS · 12.10.1
  • Fully addressedHIPAA Security Rule · 164.308(a)(6)
  • Partially addressedGDPR · Art. 33 — Notification duty implies a process.
  • Partially addressedEU AI Act · Art. 73 — Serious incident reporting for providers.
  • Fully addressedNIST AI Risk Management Framework · MANAGE 4.3