Does anyone have experience using a cyber security incident response plan flow chart? Has that been effective?

3k viewscircle icon3 Comments
Sort by:
Chief Information Security Officer in Software2 years ago

Certainly! From my perspective, a cybersecurity incident response plan flowchart is a valuable visual tool for organizations, helping to streamline the response process and ensure all critical steps are being consistently followed. When designed well and paired with regular training, it can be quite effective in guiding teams through incidents efficiently. By striving to perfect our response mechanisms, we aim to be the 'light on the hill'—showcasing best practices for the industry. It's essential, however, to review and update the flowchart periodically to reflect evolving threats and best practices.

Chief Information Security Officer in Healthcare and Biotech2 years ago

mitre attack framework can be good reference point

Director of Cybersecurity in Government2 years ago

I checked our own plan, and we don't have a flow chart. We do have a table to assess the severity of an incident. You can see it at https://www.idmanagement.gov/docs/fpki-imp.pdf. We developed our plan according to the U.S. National Institute of Standards and Technology Standard Publication 800-61 at https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf 

What kind of flow chart do you mean? A communications flow chart or a RACI flow chart?

Content you might like

Necessary given the circumstances - I fully support it17%

More clarity/communication from CISA was needed51%

Takedown was a wake-up call46%

Better strategies needed to avoid costly downtime29%

Takedown could have been avoided19%

Concerned about downstream operational impacts to customers8%

Something else (explain in the comments)2%

View Results

Very likely9%

Likely49%

Moderately likely23%

Moderately unlikely6%

Unlikely8%

Very unlikely

Unsure1%

View Results