Security Incident Reporting and Response SOP
Detect, contain and learn from security incidents fast.
The full Security Incident Reporting and Response SOP (all 7 steps, 2 controls, records and measures) is one of 36 editable Word SOPs in the SOP Template Kit: $79.
| Document no. | IT-06 | Department | IT & Security |
1. Purpose
Detect, contain and learn from security incidents fast.
2. Scope
Suspected or confirmed security incidents, including phishing, malware, data exposure, lost devices and AI systems acting outside their permissions.
3. Roles and responsibilities
| Role | Responsibility |
|---|---|
| All Staff | Report immediately. |
| Incident Lead | Coordinates response. |
| Management | Decides on notifications. |
4. Procedure
| Step | Who | What to do |
|---|---|---|
| 1 | All Staff | Report suspected incidents immediately to [security@ / hotline]; don't investigate or delete evidence. |
| 2 | Incident Lead | Log the incident, assess severity and assemble the response team. |
| 3 | Incident Lead | Contain: isolate devices, disable accounts, revoke tokens and keys. |
| + 4 more steps, 2 controls, 3 records and 3 measures in the full SOP. | ||