IT Audit Factory · Evidence-first audit operationsFree · Professional · MSP

Historical guide. This document retains its original version. See the current release guide for current build, storage and installer information.

Focused release in development: C31 supports new ISO 27001, CMMC Level 2, NIST SP 800-171 Rev. 2/3, NIST CSF 2.0 and NIST SP 800-53, HIPAA Security, ITAF ransomware readiness and PCI DSS preparation assessments. Other framework packs and advanced automation are in development. C12 is the owner-confirmed working baseline; C31 acceptance is pending.

Documentation

Incident response workflow

Maintain incident roles, escalation, timeline, evidence and recovery records.

MSP4.1.0
All documentation / MSP / 4.1.0
This reference is bundled with the 4.1.0 engine and may retain earlier UI terminology. Use the current 4.1.0 installation/security guides for the new wizard and activation steps. Its procedures apply to MSP; use the separate Free or Professional guide for those editions.

Use the approved 4.1.0 installer for your edition and confirm the version shown in the installed application. Published package availability is shown in Downloads & beta access.

IT Audit Factory — Simplified Incident Response Plan

Scope: CMMC Level 2 3.6.1 is the primary plan scope. Escalation intervals are IT Audit Factory recommended defaults, not CMMC-mandated intervals, and are customizable.

Order of Escalation

User/Reporter → Service Desk/Incident Intake → Security/IT Lead → Incident Commander → IT/Infrastructure + affected System/Application Owner → Executive Leadership → Legal/Privacy/HR/Communications/Insurer/Law Enforcement or other external parties as applicable.

SeverityInitial escalationAcknowledgement
SEV-1 CriticalImmediate5 minutes
SEV-2 HighImmediate15 minutes
SEV-3 MediumWithin 30 minutes30 minutes
SEV-4 LowWithin 4 business hours4 business hours

If there is no acknowledgement, contact the backup and advance to the next escalation level.

Operational workflow

  1. Preparation — contacts, roles, logging, backups, tooling, communication channels and authority.
  2. Detection — receive reports and record time/source/affected systems/severity.
  3. Analysis — validate, preserve evidence, determine scope and impact, classify severity.
  4. Containment — isolate with authorization and preserve evidence.
  5. Recovery — eradicate cause, restore, rotate credentials/keys as needed and monitor.
  6. User response activities — issue approved instructions and track acknowledgements/actions.
  7. Post-incident — lessons learned, POA&M/corrective action, retest and closure.

Evidence

Preserve incident ID, severity, timestamps, reporter, escalation/acknowledgement history, affected assets, commands/actions, evidence hashes, communications, containment/recovery actions, root cause, lessons learned, corrective actions and retest/closure approval.