incident response sop

Security Incident Response SOP

A security incident playbook from detection through containment, communication, and review.

incident response sopsecurity incident procedureincident response playbooksecurity runbook

Example text

Security Incident Response SOP

SOP-SEC-001: Security Incident Response

Document owner: Security Operations
On-call: Security IR rotation
Version: 1.3

Purpose

Respond to suspected or confirmed security incidents with speed, clear ownership, and auditable decisions.

Severity levels

  1. SEV-1: Active compromise or confirmed data exposure
  2. SEV-2: Likely compromise with limited blast radius
  3. SEV-3: Suspicious activity requiring investigation

Procedure

1. Detect and declare

  1. Log the alert source, time, and affected assets.
  2. Declare an incident in the IR channel with severity and incident commander.
  3. Preserve evidence; do not wipe systems before capture guidance.

2. Triage

  1. Determine user, system, and data impact.
  2. Identify whether credentials, production systems, or customer data are involved.
  3. Escalate SEV-1 to executive and legal contacts within 30 minutes.

3. Contain

  1. Isolate affected accounts or hosts.
  2. Rotate compromised credentials and revoke sessions.
  3. Block malicious indicators at network and identity layers.

4. Eradicate and recover

  1. Remove persistence mechanisms.
  2. Restore clean systems from known-good backups when needed.
  3. Confirm monitoring coverage before declaring recovery.

5. Communicate and review

  1. Send stakeholder updates on the agreed cadence.
  2. Complete a post-incident review within five business days.
  3. File follow-up actions with owners and due dates.

Done looks like

Threat is contained, systems are restored, stakeholders are informed, and corrective actions are tracked.