// CPCSC TEMPLATES · 08 OF 14

Incident response plan skeleton

Last verified: 2026-10-05

One page, with names on it and the contract reporting contacts built in. Satisfies 03.06.01 through 03.06.05 when filled in and exercised.

Free to use, edit, and share, including by an MSP for a client, under CC BY 4.0. Keep the credit "Hans Study, hans.study" and the licence with it. None of it is legal advice or a substitute for the contract clauses in front of you.

TPL-08 Static template
  1. Scope · systems and data covered: [the enclave, named]
  2. Definitions · an incident involving Specified Information is [unauthorized access, loss, disclosure, or suspected compromise of the data or the systems holding it]
  3. Roles · incident lead [name]; deputy [name]; IT or MSP contact [name]; management contact [name]
  4. Contacts · prime contractor security contact [name, channel]; contract-required government reporting contact [per clause]; cyber insurer [policy, number]; legal [name]
  5. Detection · where alerts arrive: [EDR console, log server, user reports to incident lead]
  6. Containment · isolate affected systems from the network; do not power off; preserve logs and images
  7. Eradication · confirm scope from logs; rebuild affected systems from baseline
  8. Recovery · restore from tested backups; verify before reconnecting to the enclave
  9. Reporting · what gets reported to whom, by when: [per contract clause; per Breach of Security Safeguards Regulations if personal information is involved]
  10. Review · what changed in controls afterward; entry in the remediation register

Exercise: annual tabletop, [date], attendance and scenario recorded. Plan distributed to: [roles]. Plan classification: internal, not published.

References

  1. Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171)April 2025, updated October 2025
    Canadian Centre for Cyber Securitycyber.gc.ca
  2. NIST SP 800-171 Revision 3, Protecting Controlled Unclassified Information in Nonfederal Systems and OrganizationsRevision 3
    NISTcsrc.nist.gov

Outbound links open in a new tab. Source-pinned. If a vendor moves a doc, this block gets updated.