Files
craftvia/seed/isms-vorlagenpaket-v2-en/verfahren/VA-01_Incident-Response-und-Meldeverfahren.md
T
msolarczekandClaude Opus 5 c8e6f30a27
CI / build-and-check (push) Canceled after 0s
CI / audit (push) Canceled after 0s
CI / sbom (push) Canceled after 0s
Basis: Certvia dev@a48c5fb als Fundament für Craftvia
Unveränderter Stand von certvia/dev (a48c5fb) plus Craftvia-Spezifikation
und Brandbook unter docs/craftvia/. ISMS-Module werden im Folgecommit entfernt.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-14 11:05:39 +02:00

2.8 KiB

Incident Response and Reporting Procedure

Document information Value
Document type Procedure instruction (VA-01)
Scope {{ISMS_SCOPE}}
Organisation {{ORG_NAME}}
Process owner {{ROLE_ISB}}
Approved by {{ROLE_ISB}}
Version {{DOC_VERSION}}
Date {{DOC_DATE}}
Status {{DOC_STATUS}}

1. Purpose

This procedure governs the reporting, assessment, handling and follow-up of information security incidents. It operationalises the associated policy ({{LINK:R04}}).

2. Scope

Applies within the ISMS scope ({{ISMS_SCOPE_DESCRIPTION}}).

3. Trigger

Reporting of a security event (employees, technology/monitoring, external parties) via the defined reporting path.

4. Inputs

  • Report/alert with a brief description
  • Affected systems/information (asset inventory)
  • Classification/protection need

5. Process

  1. Report the event: record the report via {{TOOL_TICKET}} or email to {{ROLE_ISB}}.
  2. Triage & classification: determine relevance, severity and category.
  3. Containment: initiate immediate measures to limit the damage.
  4. Remediation & recovery: eliminate the cause, restore normal operations.
  5. Check reporting obligations: customers/OEM, authorities, and for personal data {{ROLE_DPO}} (72-hour deadline).
  6. Documentation & lessons learned: close the incident, derive improvement measures.

6. RACI

# Step R (Execution) A (Accountable) C (Consulted) I (Informed)
1 Report the event Reporting person {{ROLE_ISB}} - -
2 Triage & classification {{ROLE_ISB}} {{ROLE_ISB}} {{ROLE_IT_LEAD}} -
3 Containment {{ROLE_IT_LEAD}} {{ROLE_ISB}} {{ROLE_ISB}} {{ROLE_MANAGEMENT}}
4 Remediation & recovery {{ROLE_IT_LEAD}} {{ROLE_IT_LEAD}} {{ROLE_ISB}} -
5 Check reporting obligations {{ROLE_ISB}} {{ROLE_MANAGEMENT}} {{ROLE_DPO}} -
6 Documentation & lessons learned {{ROLE_ISB}} {{ROLE_ISB}} {{ROLE_IT_LEAD}} {{ROLE_MANAGEMENT}}

7. Result & evidence

Documented, closed incident in {{TOOL_TICKET}}; derived measures in the ISMS tool ({{TOOL_NAME}}). Evidence is referenced in the central evidence register ({{LINK:NACHWEISREGISTER}}).

8. Key performance indicators (KPI)

  • Time to detect/acknowledge
  • Time to resolve
  • Share of reports made on time
  • Associated policy: {{LINK:R04}}
  • {{LINK:VA-02}}
  • Technical security baseline: {{LINK:BASELINE}}
  • ISA mapping matrix: {{LINK:ISA_MAPPING}}