Example text
Security Incident Response SOP
SOP-SEC-001: Security Incident Response
Document owner: Security Operations
On-call: Security IR rotation
Version: 1.3
Purpose
Respond to suspected or confirmed security incidents with speed, clear ownership, and auditable decisions.
Severity levels
- SEV-1: Active compromise or confirmed data exposure
- SEV-2: Likely compromise with limited blast radius
- SEV-3: Suspicious activity requiring investigation
Procedure
1. Detect and declare
- Log the alert source, time, and affected assets.
- Declare an incident in the IR channel with severity and incident commander.
- Preserve evidence; do not wipe systems before capture guidance.
2. Triage
- Determine user, system, and data impact.
- Identify whether credentials, production systems, or customer data are involved.
- Escalate SEV-1 to executive and legal contacts within 30 minutes.
3. Contain
- Isolate affected accounts or hosts.
- Rotate compromised credentials and revoke sessions.
- Block malicious indicators at network and identity layers.
4. Eradicate and recover
- Remove persistence mechanisms.
- Restore clean systems from known-good backups when needed.
- Confirm monitoring coverage before declaring recovery.
5. Communicate and review
- Send stakeholder updates on the agreed cadence.
- Complete a post-incident review within five business days.
- File follow-up actions with owners and due dates.
Done looks like
Threat is contained, systems are restored, stakeholders are informed, and corrective actions are tracked.