For each selected outcome, name the responsible role, operating procedure, evidence source, review frequency, dependency, and exception. Preparation evidence may include policies, critical-service and dependency maps, asset inventories, supplier responsibilities, monitoring coverage, exercise results, communication procedures, and recovery criteria. Active-response evidence may include declarations, triage decisions, action logs, incident data, notifications, containment and eradication records, restoration validation, and after-action reports.
Rev. 3 spreads responsibility beyond a computer security incident response team. Depending on the organization and incident, leadership, incident handlers, technology professionals, legal, public affairs, human resources, physical security, asset owners, and external providers may make or execute decisions. The profile should expose missing authority and handoffs rather than assigning every outcome to the security team.