# SP-036 Incident Response

Status: active. Release 26.02. Modified 2026-02-07. Licence: CC BY-SA 4.0.

Scope: End-to-end incident response pattern covering preparation, detection, triage, containment, eradication, recovery, and post-incident review. Addresses organisational structure, playbook design, communication protocols, regulatory notification, forensic evidence handling, and continuous improvement.
Use when: This pattern applies to every organisation that operates information systems -- incident response capability is not optional. It is particularly critical for: regulated financial services firms with notification obligations to FCA, PRA, BoE, or equivalent regulators, organisations subject to GDPR or equivalent data protection regulations, critical national infrastructure operators with NCSC reporting obligations,...
Not when: There are no contraindications for incident response capability -- every organisation needs it.

## Controls (33, NIST SP 800-53 ids)
- Critical (12): AT-03, AU-06, AU-09, IR-01, IR-02, IR-03, IR-04, IR-05, IR-06, IR-08, PM-14, SI-04
- Important (15): AC-02, AC-04, AT-02, AU-02, AU-03, CA-02, CA-07, CM-02, CP-10, IR-07, PL-04, PS-07, RA-05, SC-07, SI-07
- Standard (6): CP-08, PL-02, PS-01, PS-04, SA-09, SR-10

## What each critical control mitigates (12)
- AT-03 Role-based Training: T-IR-009
- AU-06 Audit Record Review, Analysis, and Reporting: T-IR-002, T-IR-003, T-IR-004, T-IR-006
- AU-09 Protection of Audit Information: T-IR-006, T-IR-009
- IR-01 Policy and Procedures: none of the threats below
- IR-02 Incident Response Training: T-IR-008, T-IR-009
- IR-03 Incident Response Testing: T-IR-008
- IR-04 Incident Handling: T-IR-001, T-IR-002, T-IR-003, T-IR-005, T-IR-006, T-IR-007, T-IR-009, T-IR-011, T-IR-012
- IR-05 Incident Monitoring: T-IR-004
- IR-06 Incident Reporting: T-IR-002, T-IR-007, T-IR-010
- IR-08 Incident Response Plan: T-IR-001, T-IR-005, T-IR-008, T-IR-012
- PM-14 Testing, Training, and Monitoring: T-IR-002, T-IR-008, T-IR-010
- SI-04 System Monitoring: T-IR-004

## Threats and the controls that mitigate them (12)
- T-IR-001 Ransomware deployment requiring immediate containment and recovery: IR-04, SC-07, CP-10, IR-08
- T-IR-002 Data breach requiring regulatory notification within defined timeframes: IR-06, IR-04, AU-06, PM-14
- T-IR-003 Business email compromise with fraudulent financial transactions: IR-04, IR-07, AT-02, AU-06
- T-IR-004 Advanced persistent threat with extended dwell time: IR-05, AU-06, SI-04, CA-07
- T-IR-005 DDoS attack disrupting critical services: IR-04, IR-08, SC-07, CP-08
- T-IR-006 Insider threat requiring evidence preservation for legal proceedings: AU-09, IR-04, PS-04, AU-06
- T-IR-007 Supply chain compromise affecting trusted software: IR-04, SI-07, SR-10, IR-06
- T-IR-008 Incident response failure due to untested or outdated plans: IR-02, IR-03, PM-14, IR-08
- T-IR-009 Evidence destruction through premature containment actions: AU-09, IR-04, IR-02, AT-03
- T-IR-010 Communication failure during crisis causing regulatory or reputational harm: IR-06, IR-07, PL-04, PM-14
- T-IR-011 Repeat compromise due to incomplete eradication: IR-04, SI-07, CM-02, RA-05
- T-IR-012 Cloud-specific incident requiring different tools and access models: IR-04, IR-08, AU-02, SA-09

## More
- The critical controls and what each mitigates, as JSON (a few KB): /api/v1/patterns/SP-036/crosswalk?emphasis=critical
- The same for every control, with its clauses in a framework: /api/v1/patterns/SP-036/crosswalk?framework={framework id}. Framework ids are listed in /llms.txt
- The pattern's prose, examples and references as JSON, 33 KB: /api/v1/patterns/SP-036
- Page for people: /patterns/sp-036/
- Related: SP-025 Advanced Monitoring and Detection; SP-029 Zero Trust Architecture; SP-031 Security Monitoring and Response; SP-034 Cyber Resilience; SP-035 Offensive Security Testing

This card, the API and the page are generated from one file. Checking one against another adds no evidence.
