01 · Explanation
Incident recognition, reporting, and recovery
Objective: Recognize possible incidents, preserve safety and evidence, use the approved reporting path, and support coordinated response and recovery without exceeding role authority.
Possible incident signals include unexpected MFA prompts, disabled security tools, unusual forwarding rules, locked or encrypted files, missing devices, unauthorized transactions, vendor notices, exposed shares, new administrators, suspicious login alerts, or reports that data reached the wrong person. Employees do not need to prove an incident before reporting. The first-actions card should name internal and alternate contacts, information to capture, prohibited actions, and emergency routes. Record what was observed, when, on which asset, by whom, and any actions already taken. Do not delete messages, wipe systems, confront a suspected actor, or investigate beyond authorization.
Response coordinates preparation, detection, analysis, containment, eradication, recovery, communication, legal and regulatory duties, and improvement under qualified leadership. Immediate actions depend on the incident; disconnecting or powering off a device can either limit harm or destroy evidence, so follow the approved responder's direction. Keep customer, employee, media, regulator, insurer, law-enforcement, and vendor communications with authorized owners. Recovery verifies restored systems, credentials, integrations, data integrity, monitoring, and business service before declaring success. Conduct a blameless after-action review, assign corrective actions, and test the changed control. Serious incidents require experienced security, legal, privacy, insurance, and possibly law-enforcement support.
Before you begin
- Confirm F01-F12 and CB01; record that exact timestamps/order, reporter/device/account identifiers, preserved artifacts, response actions, communications, decisions, approvals, recovery validation, and closure evidence are not supplied.
- STOP. If the event order, identifiers, preserved artifacts, response record, communication decision, recovery validation, or closure evidence is missing or conflicts with F01–F12/CB01, route the incident record to the authorized incident commander and security, finance, and recovery reviewers; do not claim approval or execute attribution, notification, recovery, or closure.

