Bundle catalog

deliverables bundle

Incident Response Plan

A free, open-source set of 5 Markdown files for drafting and reviewing Incident Response Plan with explicit evidence, constraints, and approval boundaries.

Use this bundle to draft or review Incident Response Plan with source evidence, open questions, owners, and approval gates kept explicit. The page previews a deliverable guide, a quality rubric, and a bundle file; the intended output is cybersecurity incident response plan and role and decision-authority matrix. Start source review with csrc.nist.gov — R3 / Final.

Project-reviewed beta

5 Markdown files · 2,211 words · no signup · CC-BY-4.0

Professional review status

No professional domain review recorded

This bundle covers security, privacy, safety, legal subject matter. It is a source-aware research aid, not professional advice, and should not be the sole basis for consequential decisions.

Review before reliance: A qualified security, privacy, incident-response, safety, or legal professional appropriate to the systems, incident, and jurisdiction.

Maintainer, editorial, or technical review addresses the bundle as a published artifact. It does not constitute legal, medical, financial, accounting, or other regulated professional approval.

Inspect before downloading

See what is inside

These previews come from the published bundle files, so you can judge the method and writing before using it.

Is this bundle right for your task?

Who it is for

  • People drafting, reviewing, approving, or relying on Incident Response Plan
  • Teams working in cybersecurity, information technology, financial services

When to use it

  • An Incident Response Plan draft needs a clear purpose, audience, evidence base, structure, and approval path.
  • An existing draft needs unsupported claims, missing sections, unresolved decisions, and reviewer comments addressed.

What you need to provide

  • The document purpose, audience, source evidence, required sections, constraints, approvers, and intended decision or action.
  • Existing drafts, templates, policies, examples, terminology, and review criteria that the output must follow.

Tasks and expected outputs

Questions it helps answer

  • define incident governance, activation, authority, escalation, evidence, communications, recovery, and closure
  • map response and notification decisions to current obligations, services, assets, data, contracts, and incident evidence
  • prevent unsupported severity, attribution, containment, notification, recovery, and closure claims

What it helps produce

  • cybersecurity incident response plan
  • role and decision-authority matrix
  • incident evidence and obligation register
  • exercise and improvement plan

Practical example

Use it with an agent

Load the bundle as context, provide the evidence named above, then adapt this example to your situation.

Provide the document purpose, audience, source evidence, required sections, constraints, approvers, and intended decision or action. Ask the agent to draft or review Incident Response Plan and return cybersecurity incident response plan with material claims tied to evidence and assumptions, open questions, reviewers, and approval gates marked. Begin with csrc.nist.gov — R3 / Final, then confirm that the reference is current and applicable. Inspect Cybersecurity Incident Response Plan Package before drafting.

Context path: bundles/deliverables/incident-response-plan

What the bundle includes

Frameworks

  • NIST SP 800-61 Rev. 3
  • NIST Cybersecurity Framework 2.0
  • incident evidence and decision ledger

Evaluations

  • Incident Response Plan quality check

Sources used to build this bundle

These are the public references behind the role definition and operating guidance. The bundle does not replace current documentation or evidence from your site.

Limitations and safe use

Do not use this for

  • Publishing, approving, or acting on a draft before its material claims, source evidence, owners, and approval gates have been reviewed.

Known limitations

  • This bundle is a planning and review aid, not live incident handling, legal advice, forensic guidance, a regulatory determination, or proof of incident readiness or compliance.
  • Severity, activation, authority, contacts, containment, evidence, reporting, notification, recovery, and closure must be tailored to current organization and incident evidence.
  • NIST and CISA guidance does not replace applicable law, contracts, regulator direction, insurer terms, system knowledge, or accountable decisions.

Safety notes

  • Protect incident, vulnerability, architecture, identity, evidence, personal, customer, legal, insurance, and law-enforcement information.
  • Require explicit authority before isolation, blocking, credential changes, evidence acquisition, restoration, notification, disclosure, law-enforcement contact, or ransom decisions.
  • Use qualified security, legal/privacy, forensics, business continuity, communications, HR, insurance, and executive reviewers as applicable.

Next step

Inspect it before relying on it

Download the bundle for use, review its source files and evidence, or read the agent guidance. If the project is useful, starring the repository helps others discover it.