Incident response plan
nounid
2820·updated Aug 30, 2026verified· unreviewed
The documentation of a predetermined set of instructions or procedures to detect, respond to, and limit consequences of a malicious cyber attacks against an organization’s information system(s).
polysemousMWE
Attested in
NIST SP 800-171 Rev 3 - Protecting CUI in Nonfederal Systems
03.06.01 ¶ 103.06.04.b ¶ 103.06.0503.06.05.a03.06.05.b03.06.05.c03.06.05.d
Classifications
Entity Type
Process0%rule-basedmulti_axis_classifier_low_confidence.v1
Sensitivity
Restricted75%llm-generatedllm:claude-haiku-4-5
Information Class
—70%llm-generatedllm:claude-haiku-4-5
Variants
- synonym
- escalation and response plan
- plural
- Incident response plans
- possessive
- Incident response plan's
- pluralpossessive
- Incident response plans'
Framework definitions
National Initiative for Cybersecurity Careers and Studies (NICCS) Cybersecurity Lexicon1 senseview framework →
- §1
- A set of predetermined and documented procedures to detect and respond to a cyber incident.
- §1
- The operational component of incident management Scope Note: The plan includes documented procedures and guidelines for defining the criticality of incidents, reporting and escalation process, and recovery procedures.
- §1
- The documentation of a predetermined set of instructions or procedures to detect, respond to, and limit consequences of a malicious cyber attacks against an organization's IT systems(s).
- §1
- The documentation of a predetermined set of instructions or procedures to detect, respond to, and limit consequences of a malicious cyber attacks against an organization's IT systems(s).
- §1
- The documentation of a predetermined set of instructions or procedures to detect, respond to, and limit consequences of a malicious cyber attacks against an organization's IT systems(s).
Federal Financial Institutions Examination Council (FFIEC) IT Examination Handbook Infobase, Glossary1 senseview framework →
- §1
- A plan that defines the action steps, involved resources, and communication strategy upon identification of a threat or potential threat event, such as a breach in security protocol, power or telecommunications outage, severe weather, or workplace violence.
- §1
- The documentation of a predetermined set of instructions or procedures to detect, respond to, and limit consequences of a malicious cyber attacks against an organization’s information system(s).
- §2 · sense_2_pending_review
- The documentation of a predetermined set of instructions or procedures to detect, respond to, and limit consequences of an incident against an organization’s IT system(s).
- §1
- The documentation of a predetermined set of instructions or procedures to detect, respond to, and limit consequences of an incident against an organization’s IT system(s).
- §1
- The documentation of a predetermined set of instructions or procedures to detect, respond to, and limit consequences of a malicious cyber attacks against an organization’s information system(s).
- §1 · attested_usage_pack_match
- No definition is given in NIST SP 800-171r3. The term is attested in use at 7 citations in that document; a definition is pending curation.Increment 2: attested in 800-171r3 without a glossary definition.
- §1 · legacy_primary
- The documentation of a predetermined set of instructions or procedures to detect, respond to, and limit consequences of a malicious cyber attacks against an organization’s information system(s).DR-088 backfill from the noun definition column
Outgoing relationships
No outgoing triples
This term is not the subject of any RDF-style relationship yet.
Incoming relationships
No incoming triples
No other term currently asserts a relationship to this one.