home/glossary/Incident response plan

Incident response plan

nounid 2820·updated Aug 30, 2026
verified· unreviewed

The documentation of a predetermined set of instructions or procedures to detect, respond to, and limit consequences of a malicious cyber attacks against an organization’s information system(s).

polysemousMWE

Attested in

NIST SP 800-171 Rev 3 - Protecting CUI in Nonfederal Systems7 citations · 7 machine-matched · observed 2026-09-01 under anchor/0.9/36451/2026-09-01
03.06.01 ¶ 103.06.04.b ¶ 103.06.0503.06.05.a03.06.05.b03.06.05.c03.06.05.d

Classifications

Entity Type

Process0%rule-basedmulti_axis_classifier_low_confidence.v1

Sensitivity

Restricted75%llm-generatedllm:claude-haiku-4-5

Information Class

70%llm-generatedllm:claude-haiku-4-5

Variants

synonym
escalation and response plan
plural
Incident response plans
possessive
Incident response plan's
pluralpossessive
Incident response plans'

Framework definitions

National Initiative for Cybersecurity Careers and Studies (NICCS) Cybersecurity Lexicon1 senseview framework →
§1
A set of predetermined and documented procedures to detect and respond to a cyber incident.
ISACA Cybersecurity Glossary1 senseview framework →
§1
The operational component of incident management Scope Note: The plan includes documented procedures and guidelines for defining the criticality of incidents, reporting and escalation process, and recovery procedures.
SEC IM Guidance Update: Cybersecurity Guidance, No. 2015-021 senseview framework →
§1
The documentation of a predetermined set of instructions or procedures to detect, respond to, and limit consequences of a malicious cyber attacks against an organization's IT systems(s).
NY DFS Part 500 (NYCRR Title 23, Chapter 1, Part 500)1 senseview framework →
§1
The documentation of a predetermined set of instructions or procedures to detect, respond to, and limit consequences of a malicious cyber attacks against an organization's IT systems(s).
NERC CIP-004-6 (Personnel & Training) v61 senseview framework →
§1
The documentation of a predetermined set of instructions or procedures to detect, respond to, and limit consequences of a malicious cyber attacks against an organization's IT systems(s).
Federal Financial Institutions Examination Council (FFIEC) IT Examination Handbook Infobase, Glossary1 senseview framework →
§1
A plan that defines the action steps, involved resources, and communication strategy upon identification of a threat or potential threat event, such as a breach in security protocol, power or telecommunications outage, severe weather, or workplace violence.
NISTIR 7298: Glossary of Key Information Security Terms, Revision 22 sensesview framework →
§1
The documentation of a predetermined set of instructions or procedures to detect, respond to, and limit consequences of a malicious cyber attacks against an organization’s information system(s).
§2 · sense_2_pending_review
The documentation of a predetermined set of instructions or procedures to detect, respond to, and limit consequences of an incident against an organization’s IT system(s).
CNSSI-4009 (Glossary of Information Assurance Terms)1 senseview framework →
§1
The documentation of a predetermined set of instructions or procedures to detect, respond to, and limit consequences of an incident against an organization’s IT system(s).
NIST SP 800-341 senseview framework →
§1
The documentation of a predetermined set of instructions or procedures to detect, respond to, and limit consequences of a malicious cyber attacks against an organization’s information system(s).
NIST SP 800-171r31 senseview framework →
§1 · attested_usage_pack_match
No definition is given in NIST SP 800-171r3. The term is attested in use at 7 citations in that document; a definition is pending curation.
Increment 2: attested in 800-171r3 without a glossary definition.
Legacy lexicon import1 senseview framework →
§1 · legacy_primary
The documentation of a predetermined set of instructions or procedures to detect, respond to, and limit consequences of a malicious cyber attacks against an organization’s information system(s).
DR-088 backfill from the noun definition column

Outgoing relationships

No outgoing triples
This term is not the subject of any RDF-style relationship yet.

Incoming relationships

No incoming triples
No other term currently asserts a relationship to this one.