Cyber Security Incident Response Plan Requirements
Create a plan detailing how to handle and report cyber security incidents effectively.
Plain language
This control is about having a clear plan for what to do if your organisation faces a cyber security problem, like a hacking attempt. It's crucial because without it, you might not respond effectively, leading to data loss, financial damage, or harm to your reputation.
Framework
ASD Information Security Manual (ISM)
Control effect
Responsive
Classifications
NC, OS, P, S, TS
ISM last updated
June 2026
Control Stack last updated
18 June 2026
E8 maturity levels
N/A
Official control statement
Systems have a cyber security incident response plan that covers the following: - guidelines on what constitutes a cyber security incident - the types of cyber security incidents likely to be encountered and the expected response to each type - how to report cyber security incidents, internally to an organisation and externally to relevant authorities - other parties that need to be informed in the event of a cyber security incident - the authority, or authorities, responsible for investigating and responding to cyber security incidents - the criteria by which an investigation of a cyber security incident would be requested from a law enforcement agency, the Australian Signals Directorate or other relevant authority - the steps necessary to ensure the integrity of evidence relating to a cyber security incident - system contingency measures or a reference to such details if they are in a separate document.
Why it matters
Without this control, a cyber security incident could cause chaos and significant harm, as no one knows who to call or what steps to take.
Operational notes
Regularly review and update your incident response plan and contact lists to ensure they're current. This keeps the team prepared and ready to act.
Implementation tips
- The business owner should designate a person to lead cyber security incident response efforts. They should ensure everyone in the organisation knows who this is and how to contact them during a security incident.
- The IT team should create a list of possible cyber security incidents your organisation might face. Describe what each incident type is and outline specific steps to respond effectively to each.
- The office manager should establish clear reporting procedures. Include details on who staff should inform internally and which external authorities, like the Australian Cyber Security Centre (ACSC), should be notified.
- The HR team should ensure employees are trained to recognise incidents and report them promptly. Regular training sessions or reminders can build awareness and readiness.
- The legal department, if available, or an external consultant should define what evidence needs to be collected during a cyber security incident. This should include maintaining records securely to preserve their integrity.
Audit / evidence tips
- Askthe documented incident response plan: Ensure there is a written plan outlining steps during an incidentLook atclarity in the roles, responsibilities, and contact detailsGoodshows an organised, detailed plan with up-to-date contact information
- Askevidence of regular incident response training sessions: Verify that training occurs and employees know how to report incidentsLook atattendance records and content summariesGoodincludes dates, topics covered, and participation lists
- Askto see the incident reporting procedures: Check that these exist and are easy to understandLook atclear instructions on who to notify internally and externallyGoodincludes roles responsible and contact details for reporting
- Askthe list of possible incident types: Ensure this list covers various scenarios that might affect the businessLook atexamples and response actionsGoodincludes specific incident descriptions and detailed response plans
- Askabout evidence preservation methods: Check how evidence is maintained during an incidentLook atprocedures ensuring integrityGoodincludes how records are secured and kept unaltered
Cross-framework mappings
How ISM-0043 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
layersPartially meets(1)expand_less | ||
| Annex A 5.26 | Annex A 5.26 requires responding to incidents according to documented procedures | |
sync_altPartially overlaps(6)expand_less | ||
| Annex A 5.1 | Annex A 5.1 requires topic-specific policies to be defined, approved, communicated and reviewed, including for areas like incident manage... | |
| Annex A 5.2 | Annex A 5.2 requires information security roles and responsibilities to be defined and allocated according to organisational needs | |
| Annex A 5.5 | Annex A 5.5 requires the organisation to establish and maintain contact with relevant authorities to enable engagement when needed | |
| Annex A 5.24 | ISM-0043 requires systems to have a cyber security incident response plan covering definitions, incident types and responses, reporting (... | |
| Annex A 5.28 | ISM-0043 requires incident response plans to include steps necessary to ensure the integrity of evidence relating to a cyber security inc... | |
| Annex A 5.29 | Annex A 5.29 requires planning to maintain information security at an appropriate level during disruption | |
handshakeSupports(3)expand_less | ||
| Annex A 5.23 | Annex A 5.23 requires the organisation to learn from security incidents and use those lessons to improve security controls and prevent re... | |
| Annex A 5.25 | Annex A 5.25 requires the organisation to assess information security events and decide whether they are incidents | |
| Annex A 6.8 | Annex A 6.8 requires a mechanism and defined channels for prompt reporting of information security events and suspected weaknesses | |
extensionDepends on(1)expand_less | ||
| Annex A 5.27 | Annex A 5.27 requires that knowledge gained from information security incidents is used to strengthen and improve information security co... | |
E8
| Control | Notes | Details |
|---|---|---|
layersPartially meets(2)expand_less | ||
handshakeSupports(2)expand_less | ||
extensionDepends on(5)expand_less | ||
linkRelated(2)expand_less | ||
ISO 42001
| Control | Notes | Details |
|---|---|---|
sync_altPartially overlaps(3)expand_less | ||
| Annex A 3.2 | Annex A 3.2 requires the organisation to define and allocate AI roles and responsibilities | |
| Annex A 8.4 | Annex A 8.4 requires the organisation to determine and document a plan for communicating incidents to users of the AI system | |
| Annex A 8.5 | Annex A 8.5 requires determining and documenting obligations to report information about the AI system to interested parties | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in Cyber security documentation
See all Guidelines for cyber security documentation controls, or browse the full ASD ISM library.