IT Audit Factory · Evidence-first audit operationsFree · Professional · MSP
Documentation

Incident response workflow

Maintain incident roles, escalation, timeline, evidence and recovery records.

MSP4.1.0
All documentation / MSP / 4.1.0
This reference is bundled with the 4.1.0 engine and may retain earlier UI terminology. Use the current 4.1.0 installation/security guides for the new wizard and activation steps. Its procedures apply to MSP; use the separate Free or Professional guide for those editions.

Use the approved 4.1.0 installer for your edition and confirm the version shown in the installed application. Published package availability is shown in Downloads & beta access.

IT Audit Factory — Simplified Incident Response Plan

Scope: CMMC Level 2 3.6.1 is the primary plan scope. Escalation intervals are IT Audit Factory recommended defaults, not CMMC-mandated intervals, and are customizable.

Order of Escalation

User/Reporter → Service Desk/Incident Intake → Security/IT Lead → Incident Commander → IT/Infrastructure + affected System/Application Owner → Executive Leadership → Legal/Privacy/HR/Communications/Insurer/Law Enforcement or other external parties as applicable.

SeverityInitial escalationAcknowledgement
SEV-1 CriticalImmediate5 minutes
SEV-2 HighImmediate15 minutes
SEV-3 MediumWithin 30 minutes30 minutes
SEV-4 LowWithin 4 business hours4 business hours

If there is no acknowledgement, contact the backup and advance to the next escalation level.

Operational workflow

  1. Preparation — contacts, roles, logging, backups, tooling, communication channels and authority.
  2. Detection — receive reports and record time/source/affected systems/severity.
  3. Analysis — validate, preserve evidence, determine scope and impact, classify severity.
  4. Containment — isolate with authorization and preserve evidence.
  5. Recovery — eradicate cause, restore, rotate credentials/keys as needed and monitor.
  6. User response activities — issue approved instructions and track acknowledgements/actions.
  7. Post-incident — lessons learned, POA&M/corrective action, retest and closure.

Evidence

Preserve incident ID, severity, timestamps, reporter, escalation/acknowledgement history, affected assets, commands/actions, evidence hashes, communications, containment/recovery actions, root cause, lessons learned, corrective actions and retest/closure approval.