B.1 Incident Response Procedures

Version: April 2025
Aligned with: ISO/IEC 27001:2022 (Annex A: A.5.24, A.5.25, A.5.26, A.5.27, A.5.28)
Applies to: All employees, contractors, and incident response team members

Purpose
To establish structured incident response procedures that ensure timely detection, containment, and recovery from information security incidents.

1. Incident Detection and Reporting
(Aligned with A.5.24 – Information security incident management planning and preparation)

1.1 Immediate Response (0-1 hour)

  • Identify and document the incident
  • Notify the Information Security Officer
  • Begin containment measures if safe to do so
  • Preserve evidence and maintain chain of custody

1.2 Assessment and Classification (1-4 hours)

  • Assess scope and impact of the incident
  • Classify incident severity level
  • Assemble appropriate response team
  • Develop containment and recovery plan

1.3 Containment and Eradication (4-24 hours)
(Aligned with A.5.26 – Response to information security incidents)

  • Implement containment measures
  • Remove threat from environment
  • Apply security patches or configuration changes
  • Verify system integrity before restoration
Direct URL: