Don't miss an insight. Subscribe to Techopedia for free.


Incident Response Plan

What Does Incident Response Plan Mean?

An incident response plan is a document that specifies how an organization will limit the risk of negative consequences should an incident occur that violates an organization's policies for acceptable use.


Incidents are often categorized by the type of risk they pose to continued operations. A cybersecurity incident response plan, for example, provides step-by-step instructions for what employees should do in response to the following types of events:

The purpose of an incident response plan is to clearly document responsibilities and linear workflows so everyone is on the same page should an event occur.

Techopedia Explains Incident Response Plan

An incident response plan ensures that an incident or breach is resolved or counteracted within the minimum possible time and with the least effect on an organization and its IT systems/environments.

The plan can be a discrete document or included as part of a larger disaster recovery and business continuity plan (BCP).

According to the SANS Institute, every incident response plan should have these six components:

  1. Staff training
  2. Incident identification
  3. Breach containment
  4. Problem eradication
  5. Data recovery
  6. Lessons learned

Related Terms