<section title="5.6. Incident Response Plans"><subsection title="Objective"><paragraph
    title="5.6.1."


><![CDATA[<p>Incident Response Plans (IRP) outline actions to take in response to an information security incident.</p>]]></paragraph>
 </subsection>
<subsection title="Context"> <block title="Scope"><paragraph
    title="5.6.2."


><![CDATA[<p>This section relates to the development of IRPs to address information security, and not physical incidents within agencies. Information relating to other mandatory documentation can be found in <a title="Document Fundamentals" href="http://nzism.gcsb.govt.nz/ism-document#Section-12683">Section 5.1 - Documentation Fundamentals</a>.</p>]]></paragraph>
</block>
</subsection>
<subsection title="Rationale &amp; Controls"> <block title="Contents of IRPs"><paragraph
    title="5.6.3.R.01."

    tags="Governance,Information Security Documentation,IRP"


><![CDATA[<p>The guidance provided on the content of IRPs will ensure that agencies have a baseline to develop an IRP with sufficient flexibility, scope and level of detail to address the majority of information security incidents that could arise.</p>]]></paragraph>
<paragraph
    title="5.6.3.C.01."

    tags="Governance,Information Security Documentation,IRP"


    classification="All Classifications"
    compliance="Must"
    cid="902"
><![CDATA[<p>Agencies MUST include, as a minimum, the following content within their IRP:</p><ul>
<li>broad guidelines on what constitutes an information security incident;</li>
<li>the minimum level of information security incident response and investigation training for system users and system administrators;</li>
<li>the authority responsible for initiating investigations of an information security incident;</li>
<li>the steps necessary to ensure the integrity of evidence supporting an information security incident;</li>
<li>the steps necessary to ensure that critical systems remain operational;&nbsp;</li>
<li>when and how to formally report information security incidents; and</li>
<li>national policy requirements for incident reporting (<a title="Information security incidents" href="http://nzism.gcsb.govt.nz/ism-document#Chapter-13097">see Chapter 7 – Information Security Incidents</a>).</li>
</ul>]]></paragraph>
<paragraph
    title="5.6.3.C.02."

    tags="Governance,Information Security Documentation,IRP"


    classification="All Classifications"
    compliance="Should"
    cid="904"
><![CDATA[<p>Agencies SHOULD include the following content within their IRP:</p><ul>
<li>clear definitions of the types of information security incidents that are likely to be encountered;</li>
<li>the expected response to each information security incident type;</li>
<li>the authority within the agency that is responsible for responding to information security incidents;</li>
<li>the criteria by which the responsible authority would initiate or request formal, police investigations of an information security incident;</li>
<li>which other agencies or authorities need to be informed in the event of an investigation being undertaken; and</li>
<li>the details of the system contingency measures or a reference to these details if they are located in a separate document.</li>
</ul>]]></paragraph>
</block>
</subsection>
</section>
