Incident Response Policy

CIAO ESSENTIAL — POLICY
C-AO/POL/CAO-470:2026 PUBLIC
Incident Response Policy
CAO-400 Cybersecurity sub-policy (CAO-470) — auto-drafted, pending panel review
Date Issued  22 June 2026
Review Date  22 June 2027
Cite as: CIAO Standard. (2026). Incident Response Policy. v1.1.3.7. C-AO/POL/CAO-470:2026. www.c-ao.com

1 · Purpose

This policy establishes the requirements for incident response policy within the CAO-400 Cybersecurity. It gives effect, in a single harmonised instrument, to the control objectives upon which recognised standards converge for this area.

2 · Scope

This policy applies to all information, systems, services, personnel and third parties within the scope of the management system.

3 · Policy statements

3.x · CAO-470 Policy Controls

outlinesatisfies·solidpartial·greyinforms

The organisation shall establish, implement and maintain a coherent and effective approach to incident response, giving effect to the organisational control objectives set out below.

DORAHIPAAISO/IEC 27001ISO/IEC 27002ISO/IEC 27017ISO/IEC 27031NIS2NIST CSF 2.0NIST SP 800-161r1NIST SP 800-53SA Cybercrimes ActSOC 2 Type II

3.1 · CAO-471 Incident Management Planning

The organisation shall establish, implement and maintain effective Incident Management Planning, giving effect to the organisational controls set out below.

ISO/IEC 27001ISO/IEC 27002ISO/IEC 27017NIST SP 800-161r1NIST SP 800-53SA Cybercrimes ActSOC 2 Type II

3.1.x · CAO-471 Organisational Controls

Essential taster — a preview of the Professional depth for this high-density control area.

Professional tier required. The organisational control objectives that decompose this area, and the technical controls beneath them, are revealed at Professional tier and above. Log in or view options ↗

3.2 · CAO-472 Incident Detection and Assessment

The organisation shall establish, implement and maintain effective Incident Detection and Assessment, giving effect to the organisational controls set out below.

ISO/IEC 27001ISO/IEC 27002ISO/IEC 27017NIST CSF 2.0NIST SP 800-53

3.2.x · CAO-472 Organisational Controls

Professional tier required. The organisational control objectives that decompose this area, and the technical controls beneath them, are revealed at Professional tier and above. Log in or view options ↗

3.3 · CAO-473 Incident Response

The organisation shall establish, implement and maintain effective Incident Response, giving effect to the organisational controls set out below.

ISO/IEC 27001ISO/IEC 27002NIS2NIST CSF 2.0NIST SP 800-53

3.3.x · CAO-473 Organisational Controls

Essential taster — a preview of the Professional depth for this high-density control area.

Professional tier required. The organisational control objectives that decompose this area, and the technical controls beneath them, are revealed at Professional tier and above. Log in or view options ↗

3.4 · CAO-474 Incident Reporting and Communication

The organisation shall establish, implement and maintain effective Incident Reporting and Communication, giving effect to the organisational controls set out below.

DORAHIPAAISO/IEC 27001ISO/IEC 27002ISO/IEC 27017NIST CSF 2.0NIST SP 800-53

3.4.x · CAO-474 Organisational Controls

Professional tier required. The organisational control objectives that decompose this area, and the technical controls beneath them, are revealed at Professional tier and above. Log in or view options ↗

3.5 · CAO-475 Incident Recovery

The organisation shall establish, implement and maintain effective Incident Recovery, giving effect to the organisational controls set out below.

ISO/IEC 27031

3.5.x · CAO-475 Organisational Controls

Professional tier required. The organisational control objectives that decompose this area, and the technical controls beneath them, are revealed at Professional tier and above. Log in or view options ↗

3.6 · CAO-476 Forensics and Learning

The organisation shall establish, implement and maintain effective Forensics and Learning, giving effect to the organisational controls set out below.

ISO/IEC 27001ISO/IEC 27002ISO/IEC 27017

3.6.x · CAO-476 Organisational Controls

Professional tier required. The organisational control objectives that decompose this area, and the technical controls beneath them, are revealed at Professional tier and above. Log in or view options ↗

4 · Roles & responsibilities

5 · Compliance, monitoring & review

Compliance with this policy is mandatory. This policy is reviewed at least annually, or upon significant change to the threat, regulatory or technological environment. Exceptions require documented risk acceptance by the accountable owner.

● LIVE CONTENT  ·  Verified 1 September 2026 at 06:29 UTC  ·  Version 1.1.3.7  ·  Always current at c-ao.com  ·  © CIAO Standard Secretariat 2026
Notices1 JulThe Monthly Standard release is scheduled for 2026-07-16.1 JulThe Annual Major release is scheduled for 2027-02-01.1 JulThe Monthly Standard release is scheduled for 2026-07-16.1 JulThe Annual Major release is scheduled for 2027-02-01.

Cite this page (APA)