NIST SP 800-61 Rev 2 — required plan sections, four-phase response lifecycle, and tabletop exercise scenario types for IR planning and testing.
NIST SP 800-61 structures incident response as four phases. The phases are a lifecycle, not a strict sequence — detection and analysis continue throughout containment, and lessons learned feed back into preparation.
| Section | Required by | What it must contain |
|---|---|---|
| Purpose & Scope | All frameworks | What the plan covers, which systems and data types are in scope, who it applies to |
| Roles & Responsibilities | HIPAA · SOC 2 · NIST | IR team members, decision authority, backup contacts, external resource contacts |
| Incident Classification | NIST · SOC 2 | Severity tiers (e.g., P1–P3), criteria for each tier, and who is notified at each level |
| Detection & Reporting Procedures | All frameworks | How employees report suspected incidents, where reports go, initial triage steps |
| Containment & Eradication Procedures | All frameworks | Specific steps for common incident types (ransomware, data breach, BEC, unauthorized access) |
| Communication Plan | HIPAA · PCI DSS · SOC 2 | Internal escalation matrix, external notification contacts (regulator, insurer, legal), customer notification templates |
| Breach Notification Timelines | HIPAA · GDPR · state laws | Regulatory deadlines by data type and jurisdiction; who drafts and approves notifications |
| Evidence Preservation | Legal · forensics | Log retention policy, chain of custody, forensic imaging procedures |
| Recovery Procedures | All frameworks | Restoration steps, backup verification, system hardening before reconnection |
| Testing & Review Schedule | HIPAA · SOC 2 · NIST | How often the plan is tested (tabletop, simulation), who reviews updates, version control |
Tabletop exercises test decision-making and communication, not technical response. A well-run tabletop takes 2–4 hours, uses injects to evolve the scenario, and ends with a structured debrief — not just a retrospective discussion.