Incident management and Incident Response
Assign topic to the user
In your template at paragraph 3.4. Treating major incidents, is stated "In the case of major incidents that could disrupt activities for an unacceptable period of time, an [Incident Response Plan as part of the Business Continuity Plan] is invoked." In the note: "If such a document is not in place, describe here the procedure in the case of a major incident."
Since Incident Response Plan is not in the toolkit, in pratice the content of your procedure is "you have to write the procedure"! This makes your template useless.
Please provide more content for that document.
Answer: Sorry for this inconvenience.
To build a Incident Response Plan you should consider the following information:
- Name, job title and contact information of personnel required to handle specific incidents (e.g., system / network administrator for IT related incidents, facilities manager for premises related incidents, etc.).
- Which extern al parties should be contacted (e.g., customers, partners, media, public services / authorities, etc.), in which situation, through which communication channel (e.g., by phone, e-mail, press conference, etc.) and by whom.
- Types of incidents that should be handled by the plan (e.g., fire, premises evacuation, service failure, etc.)
- Details on how to treat each of the identified incident (e.g., for fire, summon the fire brigade, start premise evacuation, call fire department, etc.)
These articles will provide you further explanation about incident management and response plan:
- How to handle incidents according to ISO 27001 A.16 https://advisera.com/27001academy/blog/2015/10/26/how-to-handle-incidents-according-to-iso-27001-a-16/
- How to write business continuity plans? https://advisera.com/27001academy/blog/2010/04/08/how-to-write-business-continuity-plans/
These materials will also help you regarding incident management and response plan:
- ISO 27001 Annex A Controls in Plain English https://advisera.com/books/iso-27001-annex-controls-plain-english/
- Writing a business continuity plan according to ISO 22301 [free webinar] https://advisera.com/27001academy/webinar/writing-a-business-continuity-plan-according-to-iso-22301-free-webinar-on-demand/
If you think you still need more information, included in you toolkit you can schedule a meeting with one of our expert so he can help you build response plans that can fulfill your needs. To schedule a meeting, please access this link: https://advisera.com/27001academy/consultation/
By the way, the Incident Response Plan template is included in the ISO 22301 Toolkit, you can see here how this document looks like: https://advisera.com/27001academy/documentation/incident-response-plan/
Comment as guest or Sign in
Dec 22, 2017