Incident Response Plan

Why Trust Techopedia

What Does Incident Response Plan Mean?

An incident response plan is a document that specifies how an organization will limit the risk of negative consequences should an incident occur that violates an organization's policies for acceptable use.


Incidents are often categorized by the type of risk they pose to continued operations. A cybersecurity incident response plan, for example, provides step-by-step instructions for what employees should do in response to the following types of events:

The purpose of an incident response plan is to clearly document responsibilities and linear workflows so everyone is on the same page should an event occur.

Techopedia Explains Incident Response Plan

An incident response plan ensures that an incident or breach is resolved or counteracted within the minimum possible time and with the least effect on an organization and its IT systems/environments.

The plan can be a discrete document or included as part of a larger disaster recovery and business continuity plan (BCP).

According to the SANS Institute, every incident response plan should have these six components:

  1. Staff training
  2. Incident identification
  3. Breach containment
  4. Problem eradication
  5. Data recovery
  6. Lessons learned

Related Terms

Margaret Rouse
Technology Expert
Margaret Rouse
Technology Expert

Margaret is an award-winning technical writer and teacher known for her ability to explain complex technical subjects to a non-technical business audience. Over the past twenty years, her IT definitions have been published by Que in an encyclopedia of technology terms and cited in articles by the New York Times, Time Magazine, USA Today, ZDNet, PC Magazine, and Discovery Magazine. She joined Techopedia in 2011. Margaret's idea of a fun day is helping IT and business professionals learn to speak each other’s highly specialized languages.