Define the incident type and activation criteria first. Name the systems, services, data, users, suppliers, and environments the playbook covers, plus conditions that require a different playbook or specialist help. State the severity inputs, incident coordinator, response roles, alternates, decision authority, communication routes, safety constraints, and dependencies.
Then give an ordered but adaptable route through detection and validation, notification, triage, analysis, containment, eradication, recovery, reporting, and conclusion. Responders should be able to see the objective, required inputs, approved actions, evidence precautions, decision owner, output, and escalation trigger for every major step.
Build playbooks around the incident types and assets that the risk assessment says the organization needs to handle. ISO/IEC 27035-3 examples include malicious email or attachments, web attacks, brute-force or denial-of-service activity, supply-chain compromise, impersonation, improper use, and loss or theft of devices or media. These are starting points, not a complete taxonomy. Keep an exception route for an unknown incident type, with a default decision authority and a time limit for management approval.