Skip to content

Incident Response Checklist


PoleHodnota
Incident IDINC-[YYYY]-[NNN]
Datum detekce[PLACEHOLDER: DD.MM.YYYY HH:MM]
Severity☐ Critical / ☐ High / ☐ Medium / ☐ Low
Type☐ Data Breach / ☐ Security / ☐ AI / ☐ Availability
Status☐ Open / ☐ Contained / ☐ Eradicated / ☐ Recovered / ☐ Closed
Incident Commander[PLACEHOLDER]

Phase 1: Detection & Initial Response (T+0 to T+1h)

Section titled “Phase 1: Detection & Initial Response (T+0 to T+1h)”
#AkceStatusČasKdo
1.1.1Incident detected
1.1.2Source of detectionSIEM/User/External/Other
1.1.3Initial severity assessment
1.1.4Incident ticket created
#AkceStatusČasKdo
1.2.1CISO notified
1.2.2DPO notified (if data breach)
1.2.3Incident Commander assigned
1.2.4IRT activated
1.2.5War room / Slack channel created
OtázkaOdpověď
Co se stalo?[PLACEHOLDER]
Kdy to začalo?[PLACEHOLDER]
Které systémy jsou dotčeny?[PLACEHOLDER]
Jsou dotčena data?☐ Ano / ☐ Ne / ☐ Neznámo
Jsou dotčena osobní data?☐ Ano / ☐ Ne / ☐ Neznámo
Je služba dostupná?☐ Ano / ☐ Ne / ☐ Částečně

#AkceStatusČasKdo
2.1.1Isolate affected systems
2.1.2Block malicious IPs/accounts
2.1.3Disable compromised accounts
2.1.4Enable enhanced monitoring
#AkceStatusČasKdo
2.2.1Capture system logs
2.2.2Memory dump (if applicable)
2.2.3Network traffic capture
2.2.4Screenshot/photo evidence
2.2.5Chain of custody documented
#AkceStatusČasKdo
2.3.1Status update to management
2.3.2Internal communication (if needed)
2.3.3Customer communication drafted

#AkceStatusČasKdo
3.1.1Log analysis
3.1.2Malware analysis (if applicable)
3.1.3Attack vector identified
3.1.4Scope determined
3.1.5Timeline reconstructed
OblastDopadDetail
Systems affected[PLACEHOLDER]
Data affected[PLACEHOLDER]
Users affected[PLACEHOLDER]
Business impact[PLACEHOLDER]
Financial impact[PLACEHOLDER]

3.3 Data Breach Assessment (if applicable)

Section titled “3.3 Data Breach Assessment (if applicable)”
OtázkaOdpověď
Jaká data byla dotčena?[PLACEHOLDER]
Kolik záznamů?[PLACEHOLDER]
Kolik subjektů?[PLACEHOLDER]
Byla data šifrovaná?☐ Ano / ☐ Ne
Byl klíč kompromitován?☐ Ano / ☐ Ne / ☐ Neznámo
Bylo k datům přistoupeno?☐ Ano / ☐ Ne / ☐ Neznámo
Byla data exfiltrována?☐ Ano / ☐ Ne / ☐ Neznámo

#AkceStatusČasKdo
4.1.1Malware removed
4.1.2Vulnerability patched
4.1.3Compromised credentials rotated
4.1.4Security controls enhanced
4.1.5System hardening completed

#AkceStatusČasKdo
5.1.1Systems restored from backup
5.1.2Systems validated
5.1.3Services restored
5.1.4Enhanced monitoring in place
5.1.5Return to normal operations

AutoritaRequiredDeadlineStatusDatum
ÚOOÚ (GDPR)☐ Ano / ☐ Ne72h
NÚKIB (NIS2)☐ Ano / ☐ Ne24h initial
Subjects (GDPR)☐ Ano / ☐ NeASAP
RecipientStatusDatum
Board
Customers
Partners
Media
Insurance

#AkceStatusDatumKdo
7.1.1Incident report finalized
7.1.2Timeline documented
7.1.3Root cause documented
7.1.4Evidence archived
#AkceStatusDatumKdo
7.2.1Post-mortem meeting scheduled
7.2.2Post-mortem completed
7.2.3Lessons learned documented
7.2.4Action items assigned
#AkceOwnerDeadlineStatus
1[PLACEHOLDER]
2[PLACEHOLDER]
3[PLACEHOLDER]

ČasUdálost
T+0[PLACEHOLDER: Detection]
T+Xh[PLACEHOLDER: Event]
T+Xh[PLACEHOLDER: Event]
T+Xh[PLACEHOLDER: Event]
T+Xd[PLACEHOLDER: Resolution]

RoleJménoPodpisDatum
Incident Commander
CISO
DPO (if data breach)
CEO (if critical)