Skip to main content

Incident Response Program Plan

A response planning project defining roles, escalation paths, communications, and post-incident improvement activities.

Organization
Cybersecurity Internship Portfolio
Duration
2 weeks
Project Type
Incident Response
NIST CSFCIS Controls

Objective

Develop an incident response capability and validate it through tabletop exercises.

NIST CSFCIS Controls

Step-by-Step Execution

  1. Step 1

    Developed Incident Response Policy

    • Created policy expectations for incident handling and response ownership.
  2. Step 2

    Created Playbooks

    • Created playbooks for phishing, ransomware, and insider threats.
  3. Step 3

    Facilitated Tabletop Exercise

    • Used discussion-based exercises to validate response readiness.
  4. Step 4

    Conducted Lessons Learned Review

    • Documented improvement opportunities through an after-action review.

Deliverables

Preparedness

Incident Response Plan

Documented response lifecycle, roles, escalation, and communication expectations.

Reduces ambiguity when timely decisions matter.

Response Playbooks

Incident Response Playbooks

Playbooks for phishing, ransomware, and insider threat scenarios.

Gives response teams scenario-specific guidance during high-pressure events.

Lessons Learned

After-Action Report

Report capturing tabletop exercise observations and improvement opportunities.

Turns exercise findings into a practical improvement record.

Skills & Insights Gained

Incident response planningCrisis managementTeam collaborationIncident documentation

Continue exploring

Governance

Governance Policy Development

A structured policy development engagement aligning security expectations with business objectives and recognized frameworks.

ISO 27001NIST CSFCIS Controls
View case study

Internal Audit

Internal Cybersecurity Audit

An internal assessment that reviewed security controls, documented gaps, and produced a prioritized remediation roadmap.

NIST CSFCIS ControlsISO 27001
View case study

Risk Management

Enterprise Risk Assessment

A risk assessment project documenting assets, threats, likelihood, impact, and treatment options for management review.

CIS RAMNIST CSFISO 27001
View case study