1 Executive Summary
Purpose & Importance
Scope
Applicability
2Organization Overview
Company Information
Company:
Location:
Employees:
Business:
CISO / Security Lead:
IRP Review Date:
CMMC Level:
CUI & Security Assets in Scope
CUI Assets
Security Protection Assets
Network Segmentation
3Incident Response Team Structure
Fill in the contact and responsibility details for each role. Use the button below to add additional roles as needed.
π· Incident Response Manager
Primary:
Backup:
Email:
Phone:
Responsibilities:
πΆ Security Analyst
Primary:
Backup:
Email:
Phone:
Responsibilities:
π§ IT Operations Lead
Primary:
Backup:
Email:
Phone:
Responsibilities:
π’ Communications Officer
Primary:
Backup:
Email:
Phone:
Responsibilities:
4Incident Classification & Prioritization
Define the incident categories and response time targets for your organization. Edit each priority tier with the specific incident types relevant to your case study.
π΄ CRITICAL β Priority 1
π HIGH β Priority 2
π‘ MEDIUM β Priority 3
π’ LOW β Priority 4
5Incident Response Lifecycle
Describe your organization's activities in each phase of the NIST SP 800-61 incident response lifecycle. Click βοΈ Edit Mode to edit phase descriptions.
Preparation
Detection & Analysis
Containment
Eradication
Recovery
Lessons Learned
6Detection and Analysis Procedures
Detection Sources
Analysis Procedures
Evidence Handling
7Containment and Eradication Strategies
Containment Strategies
Short-term Containment
Long-term Containment
Eradication Procedures
Recovery Procedures
Post-Incident Activities
8Evidence Preservation & Forensics
Forensic Collection Priorities
Chain of Custody Procedures
Forensic Tools & Resources
9Communication and Reporting Protocols
Internal Communication
External Reporting Requirements
Emergency Contact Directory
DIBNet Portal:
DoD Cyber Crime Center (DC3):
FBI Cyber Division:
CISA:
Cyber Insurance Carrier:
Legal Counsel:
External Forensics Vendor:
10Training and Exercise Programs
Training Requirements
Exercise Schedule
Tabletop Exercise Scenarios
Use the π― Tabletop Exercise button in the toolbar to launch the interactive scenario panel. Scenarios added there will appear below when saved.
No tabletop scenarios recorded yet β use the Tabletop Exercise button to add scenarios.