What it has to decide
- A definition of incident, and of severity
Severity has to be assignable in the first ten minutes by someone who does not yet know what happened. Definitions that need the full picture are useless at the moment they are needed.
- Who may declare, at any hour
Name the roles that can declare an incident without escalation. If declaration requires waking an executive, declaration will be delayed, and delay is the whole cost.
- The authority granted on declaration
State that the incident lead may isolate systems, revoke credentials and take services offline without further approval. This is the clause that turns a plan into a response.
- Notification obligations and their clocks
Regulators, customers, insurers and boards each have a clock. Australian entities should note the Notifiable Data Breaches scheme and, where applicable, SOCI obligations. Put the actual hours in the policy.
- Evidence handling
Say that preservation precedes remediation, and who decides when it does not. The instinct under pressure is to rebuild the box, which destroys the only record of what happened.
- Post-incident review, with a deadline
A review that happens whenever the team gets to it does not happen. Set a number of business days and an owner for the actions arising.
How it is usually got wrong
- The plan has never been exercised, so the first time the call tree is used is during a real incident, and it is out of date.
- Severity definitions require knowing the impact, which is not knowable early, so everything is triaged as medium until it is obviously critical.
- Responders lack the standing authority to disconnect anything, so the first hour is spent seeking permission.
- Notification clocks are described as "as soon as practicable" rather than in hours, so the clock is argued about while it runs.
- Post-incident actions are recorded and never tracked to closure, so the same incident recurs.
Worked extract
What a decision looks like once it has been madeAny member of the security operations team, service desk or engineering on-call rotation may declare a security incident at any hour without prior escalation. On declaration, the assigned Incident Lead is authorised to isolate systems from the network, revoke credentials, disable accounts and withdraw services from production without further approval, and is expected to do so where containment requires it. Preservation of evidence takes precedence over restoration of service unless the Incident Lead judges that continued unavailability presents a greater harm, in which case the judgement and its reasoning are recorded at the time. A post-incident review is held within ten business days for any incident rated High or Critical, chaired by someone who was not part of the response.