← CISM: manage security, risk, and incidents
07 / 8 · 30 MIN

Prepare response and continuity

Define criteria, authority, communication, and recovery before an incident.

Concept and mechanism

Incident response requires preparation integrated into risk management. NIST SP 800-61 revision 3 connects response to CSF 2.0; the organization needs authority, contacts, tools, evidence, and learning, not merely a rigid task sequence. Define event classification and when coordination activates. Affected-server count is insufficient to measure severity: one system may support critical settlement. A credible alert may require response before final root cause exists. Preserve the distinction between indication, confirmed fact, and hypothesis during escalation. Define who can authorize business-impacting containment and which actions the plan already authorizes.

Guided application

The BIA helps establish impact over time, dependencies, and priorities. RTO defines a recovery-time objective; RPO limits the acceptable data gap under requirements. If service stops at 09:00 and is validated at 09:25, a 30-minute RTO was met. If data only reaches 08:48, there is a potential 12-minute gap, exceeding a five-minute RPO. Test contacts, backups, alternative channels, and recovery capability. An exercise meeting only creates improvement if gaps have owners, deadlines, and retesting. If the normal channel is compromised, the alternative should be verified and participants validated.

IN PRACTICE

The primary contact fails during an exercise: correct the chain and confirm the backup receives and owns escalation.

Common pitfalls

RTO as RPO; machine count as impact; exercise attendance as readiness.

Related topics: Contain, recover, and learn · Governance, strategy, and authority

Take this idea with you

Prepare decisions and demonstrate capability before incident pressure.

Create account

Reference: Incident Response Recommendations and Considerations · CISM current outline before November 3, 2026