Which incident-management roles should be assigned?
Assign an (IMT) to maintain the capability and an to lead each case. Define internal or external (IRTs), points of contact, monitoring, business and asset owners, legal and privacy advisers, communications, continuity, HR, evidence specialists, and crisis management as the organization needs them.
ISO/IEC 27035-1 treats a as one possible IRT, while ISO/IEC 27035-3 recommends establishing a CSIRT for ICT incident response operations. Smaller organizations and outsourced environments can combine roles, but authority, availability, conflicts, supplier handoffs, and accountability should remain explicit. The plan should show who acts, who approves, who is informed, and who can accept residual risk.
- Publish primary and backup contacts with secure out-of-band routes and availability expectations.
- Pre-authorize urgent containment boundaries and define when executive, crisis, safety, legal, privacy, customer, supplier, or authority escalation is required.
- Exercise internal and external relationships, including managed service providers and specialist responders, before relying on them.
Primary ISO listing for incident management principles and process.
Primary ISO listing for planning, preparing, and lessons-learned guidance.
Lists common incident response roles and responsibilities, including leadership, incident handlers, legal, public affairs and media relations, asset owners, and third parties.