Use the approved 4.1.0 installer for your edition and confirm the version shown in the installed application. Published package availability is shown in Downloads & beta access.
IT Audit Factory — Simplified Incident Response Plan
Order of Escalation
User/Reporter → Service Desk/Incident Intake → Security/IT Lead → Incident Commander → IT/Infrastructure + affected System/Application Owner → Executive Leadership → Legal/Privacy/HR/Communications/Insurer/Law Enforcement or other external parties as applicable.
Recommended defaults
| Severity | Initial escalation | Acknowledgement |
|---|---|---|
| SEV-1 Critical | Immediate | 5 minutes |
| SEV-2 High | Immediate | 15 minutes |
| SEV-3 Medium | Within 30 minutes | 30 minutes |
| SEV-4 Low | Within 4 business hours | 4 business hours |
If there is no acknowledgement, contact the backup and advance to the next escalation level.
Operational workflow
- Preparation — contacts, roles, logging, backups, tooling, communication channels and authority.
- Detection — receive reports and record time/source/affected systems/severity.
- Analysis — validate, preserve evidence, determine scope and impact, classify severity.
- Containment — isolate with authorization and preserve evidence.
- Recovery — eradicate cause, restore, rotate credentials/keys as needed and monitor.
- User response activities — issue approved instructions and track acknowledgements/actions.
- Post-incident — lessons learned, POA&M/corrective action, retest and closure.
Evidence
Preserve incident ID, severity, timestamps, reporter, escalation/acknowledgement history, affected assets, commands/actions, evidence hashes, communications, containment/recovery actions, root cause, lessons learned, corrective actions and retest/closure approval.