Creating IRPs
An IRP is a document that describes the procedures to follow in case of a security incident. The management area must support this document.
The IRP generally defines a route to follow when a security incident occurs. This plan must be consistent with existing organizational capacity, resources, and infrastructure.
The elements of an IRP are listed here:
- Mission
- Objectives and strategies
- Management approval
- The organization's position on IR
- Metrics to measure the capacity and efficiency of the plan
- Path to raise the maturity levels of the organization's IR capability
- Definition of alignment of the plan with the organization
This last point is crucial since one of the objectives of IR is to help in the BC process and the organization's operations.
This plan, as with any plan or policy, should be reviewed periodically (according to National Institute of Standards and Technology (NIST) recommendations...