IT Audit Factory · Evidence-first audit operationsFree · Professional · MSP

Historical guide. This document retains its original version. See the current release guide for current build, storage and installer information.

Focused release in development: C31 supports new ISO 27001, CMMC Level 2, NIST SP 800-171 Rev. 2/3, NIST CSF 2.0 and NIST SP 800-53, HIPAA Security, ITAF ransomware readiness and PCI DSS preparation assessments. Other framework packs and advanced automation are in development. C12 is the owner-confirmed working baseline; C31 acceptance is pending.

Archived guide — original release identity

This guide describes a previous release. Use the current 4.1.0 documentation for new installations.

Documentation

Incident response workflow

Maintain incident roles, escalation, timeline, evidence and recovery records.

MSPR68 bundled reference
All documentation / MSP / R68 bundled reference
This reference is bundled with the R68 engine and may retain earlier UI terminology. Use the current R68 installation/security guides for the new wizard and activation steps. Its procedures apply to MSP; use the separate Free or Professional guide for those editions.

IT Audit Factory — Simplified Incident Response Plan

Scope: CMMC Level 2 3.6.1 is the primary plan scope. Escalation intervals are IT Audit Factory recommended defaults, not CMMC-mandated intervals, and are customizable.

Order of Escalation

User/Reporter → Service Desk/Incident Intake → Security/IT Lead → Incident Commander → IT/Infrastructure + affected System/Application Owner → Executive Leadership → Legal/Privacy/HR/Communications/Insurer/Law Enforcement or other external parties as applicable.

SeverityInitial escalationAcknowledgement
SEV-1 CriticalImmediate5 minutes
SEV-2 HighImmediate15 minutes
SEV-3 MediumWithin 30 minutes30 minutes
SEV-4 LowWithin 4 business hours4 business hours

If there is no acknowledgement, contact the backup and advance to the next escalation level.

Operational workflow

  1. Preparation — contacts, roles, logging, backups, tooling, communication channels and authority.
  2. Detection — receive reports and record time/source/affected systems/severity.
  3. Analysis — validate, preserve evidence, determine scope and impact, classify severity.
  4. Containment — isolate with authorization and preserve evidence.
  5. Recovery — eradicate cause, restore, rotate credentials/keys as needed and monitor.
  6. User response activities — issue approved instructions and track acknowledgements/actions.
  7. Post-incident — lessons learned, POA&M/corrective action, retest and closure.

Evidence

Preserve incident ID, severity, timestamps, reporter, escalation/acknowledgement history, affected assets, commands/actions, evidence hashes, communications, containment/recovery actions, root cause, lessons learned, corrective actions and retest/closure approval.

Guide basis

R68 package: Incident-Response-Plan.html

Published as a website guide on 1 October 2026. Where a bundled reference is older, the version-specific guide and installed interface take precedence.