5.1.1. Incident Response Plan Development
💡 First Principle: An incident response plan's real job is to remove decisions from the moment of highest pressure — who has authority to declare an incident, who gets notified, and what the first three actions are should all be answered before the first alert ever fires.
A plan built during a crisis is not a plan; it is an argument happening in real time while damage accumulates. Effective IR plan development documents an owner for the plan itself, a defined escalation chain (who can declare an incident, who must be notified and in what order), and enough procedural detail that a mid-level analyst can begin the first response actions correctly without waiting for a senior decision-maker to become available. The plan also has to specify its own boundaries — what it does not cover, such as full business continuity, which is a related but separate plan (5.1.3).
⚠️ Exam Trap: An IR plan is sometimes assumed to fully overlap with a BCP. The correct answer treats them as integrated but distinct — the IR plan governs the security-incident response itself; the BCP governs keeping the broader business running.
Reflection Question: During an active incident, two managers disagree about who has authority to take a production system offline. What does this reveal about a gap in your incident response plan, and when should that gap have been closed?