Cybersecurity GRC 17 items
Cybersecurity Incident Response Readiness Checklist
Assesses incident response capability across preparation, detection, containment, eradication, recovery, and post-incident activity.
NIST 800-61r2ISO 27001:2022SOC 2
Free PDF · enter your email to download.
Preparation
- Is a documented incident response plan approved and maintained? *
- Is an incident response team defined with roles and contact information? *
- Are severity classification and escalation criteria defined? *
- Are IR tools, jump kits, and communication channels prepared in advance? *
Detection & Analysis
- Are detection sources (SIEM, EDR, IDS) monitored to identify incidents? *
- Is a process defined to triage and validate alerts as incidents? *
- Are incidents documented with timelines and evidence from the outset? *
Containment, Eradication & Recovery
- Are short-term and long-term containment strategies defined? *
- Are procedures defined to eradicate threats and remediate root cause? *
- Is evidence preserved with proper chain of custody for potential legal action? *
- Are recovery and validation steps defined to restore systems safely? *
Communication & Reporting
- Are internal and external notification requirements (regulators, customers) defined? *
- Are breach notification timelines mapped to applicable regulations? *
- Is a designated spokesperson identified for external communications? *
Post-Incident Activity
- Is a lessons-learned review conducted after major incidents? *
- Are tabletop exercises conducted at least annually? *
- When was the most recent incident response exercise conducted?
Download the full Cybersecurity Incident Response Readiness Checklist checklist
Get it as a clean, printable PDF — free.
