ID.IM-04.190

Do your contingency plans include comprehensive contact information, communication procedures, scenario handling processes, and clear criteria for prioritization, escalation, and elevation?

Explanation

Effective contingency plans must include detailed contact information for all key personnel, specific communication channels and procedures, documented processes for handling common scenarios, and clear criteria for when to prioritize, escalate or elevate issues. Without these elements, organizations risk delayed responses, miscommunication, and inconsistent handling of incidents during critical situations. Evidence of fulfillment could include a documented contingency plan template or actual plan that contains sections for: contact directories with roles and alternates, communication protocols with channels and escalation paths, scenario-based response procedures, and a decision matrix for prioritization and escalation criteria.

Implementation Example

Include contact and communication information, processes for handling common scenarios, and criteria for prioritization, escalation, and elevation in all contingency plans

ID: ID.IM-04.190

Context

Function
ID: IDENTIFY
Category
ID.IM: Improvement
Sub-Category
Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved

ResponseHub is the product I wish I had when I was a CTO

Previously I was co-founder and CTO of Progression, a VC backed HR-tech startup used by some of the biggest names in tech.

As our sales grew, security questionnaires quickly became one of my biggest pain-points. They were confusing, hard to delegate and arrived like London busses - 3 at a time!

I'm building ResponseHub so that other teams don't have to go through this. Leave the security questionnaires to us so you can get back to closing deals, shipping product and building your team.

Signature
Neil Cameron
Founder, ResponseHub
Neil Cameron