First SOC 2 program
A credible starting point
Create a concise plan with declaration criteria, named roles and backups, severity examples, contact methods, a response checklist, evidence-preservation steps, and an annual practice scenario.
Incident Response
The incident response plan defines roles, escalation paths, severity levels, communication procedures, containment steps, recovery responsibilities, and required evidence for security and availability incidents.
Use this guide to put the control into operation, decide what records to retain, and check that an auditor can trace the evidence back to the work your team performed.
Maintained by GreenHat Security · Reviewed August 21, 2026
When a security or availability incident occurs, the team can quickly declare it, assign leadership, coordinate containment and recovery, preserve important facts, and make communication decisions through a known process.
First SOC 2 program
Create a concise plan with declaration criteria, named roles and backups, severity examples, contact methods, a response checklist, evidence-preservation steps, and an annual practice scenario.
As the company scales
Add service-specific playbooks, on-call integration, legal and privacy decision paths, out-of-band communications, trained role rotations, exercise coverage, and metrics from real incidents and simulations.
Give responders plain examples and a clear route for declaring suspected security, privacy, availability, or customer-impacting incidents without waiting for perfect certainty.
You should end up with: Incident declaration and severity guide
Name primary and backup incident commanders, technical leads, communications owners, record keepers, and legal or privacy contacts, including the decisions each may make.
You should end up with: Current incident role and authority roster
Create usable steps for intake, classification, escalation, containment, evidence preservation, investigation, recovery validation, communication, and closure.
You should end up with: Approved incident response plan and quick checklist
Document primary and alternate contact methods, secure collaboration locations, executive escalation, and how the team will work if ordinary identity or messaging is unavailable.
You should end up with: Incident contact and out-of-band communication plan
Use a consistent incident record for timestamps, facts, hypotheses, actions, approvals, customer impact, evidence links, and unresolved questions.
You should end up with: Incident record format and evidence location
Run a realistic scenario, observe role handoffs and decisions, record gaps, update the plan, and verify high-risk corrective actions.
You should end up with: Exercise report and closed improvement actions
Build the evidence set in three layers: what defines the control, who approved or reviewed it, and what proves it operated. Collect operating records when the work happens so they remain dated, attributable, correctly scoped, and traceable to the underlying activity.
Before sharing, remove unrelated personal or customer data, never expose passwords, tokens, or secret values, preserve enough source context to authenticate the record, and use the secure exchange approved for the engagement.
Documents that define the control, its scope, ownership, and expected way of working.
Confirm what the record proves
The company has an approved, current response process for declaration, command, escalation, containment, evidence preservation, investigation, recovery, communication, and closure.
Include this context
Scope and effective version
Include this context
Approver and date
Include this context
Declaration route
Include this context
Response phases
Include this context
Communication paths
Include this context
Evidence location
Weak evidence to avoid
A generic plan that does not identify the company's systems, declaration channel, current contacts, decision authority, or effective version.
Confirm what the record proves
Primary and backup responders are named by role, reachable, and authorized to make defined technical, executive, privacy, legal, and communication decisions.
Include this context
Response role
Include this context
Primary assignee
Include this context
Backup assignee
Include this context
Contact method
Include this context
Decision authority
Include this context
Last verified date
Weak evidence to avoid
A list of department names with no primary or backup person, contact route, authority, or verification date.
Confirm what the record proves
Responders use consistent business, customer, data, service, and technical factors to classify incidents and reach the appropriate escalation path.
Include this context
Severity levels
Include this context
Decision factors
Include this context
Company-specific examples
Include this context
Required escalation
Include this context
Response owner
Include this context
Effective version
Weak evidence to avoid
Vendor severity labels copied without company examples, customer or data impact, escalation recipients, or an approved version.
Records showing that an accountable person reviewed, approved, challenged, or accepted the work.
Confirm what the record proves
The response team practiced a defined scenario, exercised role and communication decisions, identified gaps, and assigned improvements.
Include this context
Scenario and date
Include this context
Participants and roles
Include this context
Timeline or prompts
Include this context
Decisions made
Include this context
Findings
Include this context
Actions and owners
Weak evidence to avoid
A calendar invite for an incident meeting with no scenario, attendance, decisions, findings, or corrective-action record.
Type 1
The current approved response plan, verified role and contact roster, severity and declaration paths, secure evidence location, and a recent exercise or actual incident record showing the process is usable at the review date.
Type 2
Every declared security, privacy, availability, or customer-impacting incident during the review period and every incident-response exercise due under the period-effective exercise schedule, including completed, cancelled, missed, and rescheduled exercises. If no incidents occurred, retain a full-period zero-result incident-register export, reconciled intake-source exports, and an attributable management confirmation rather than creating a fictional incident record.
Reconcile the full-period incident register to declared incidents found in security cases, on-call records, service incidents, and customer-support escalation sources, and reconcile the exercise schedule to exercise records. For a zero-incident period, preserve the exact full-period queries, source coverage, zero-result exports, and management confirmation; an exercise demonstrates preparedness but is not an actual incident occurrence.
Use this checklist to prepare for procedures an auditor may perform. The exact steps and sample selection depend on your engagement scope and the service auditor's professional judgment.
Determine whether the control is designed to achieve this result: When a security or availability incident occurs, the team can quickly declare it, assign leadership, coordinate containment and recovery, preserve important facts, and make communication decisions through a known process.
Compare the documented owner with the intended role (CISO / Incident Commander / Privacy-Legal Owner), then compare dated records with the stated cadence: Per event/incident; tabletop at least annually.
Reconcile the full-period incident register to declared incidents found in security cases, on-call records, service incidents, and customer-support escalation sources, and reconcile the exercise schedule to exercise records. For a zero-incident period, preserve the exact full-period queries, source coverage, zero-result exports, and management confirmation; an exercise demonstrates preparedness but is not an actual incident occurrence.
The current approved response plan, verified role and contact roster, severity and declaration paths, secure evidence location, and a recent exercise or actual incident record showing the process is usable at the review date.
Every declared security, privacy, availability, or customer-impacting incident during the review period and every incident-response exercise due under the period-effective exercise schedule, including completed, cancelled, missed, and rescheduled exercises. If no incidents occurred, retain a full-period zero-result incident-register export, reconciled intake-source exports, and an attributable management confirmation rather than creating a fictional incident record.
Documents that define the control, its scope, ownership, and expected way of working.
For each selected record, confirm it demonstrates The company has an approved, current response process for declaration, command, escalation, containment, evidence preservation, investigation, recovery, communication, and closure.
For each selected record, confirm it demonstrates Primary and backup responders are named by role, reachable, and authorized to make defined technical, executive, privacy, legal, and communication decisions.
For each selected record, confirm it demonstrates Responders use consistent business, customer, data, service, and technical factors to classify incidents and reach the appropriate escalation path.
Records showing that an accountable person reviewed, approved, challenged, or accepted the work.
For each selected record, confirm it demonstrates The response team practiced a defined scenario, exercised role and communication decisions, identified gaps, and assigned improvements.
Use the categories that apply to this control: connect any policy or design artifact to its approval or review record, then trace a selected operating record through execution, result, and any exception or remediation.
These identifiers help you navigate related Trust Services Criteria. They do not reproduce the criteria or prove that this control fully addresses them in your environment.
Confirm final scope, mappings, and testing expectations with your service auditor. SOC 2® is an AICPA trademark; GreenHat Security is not affiliated with or endorsed by AICPA.