{"id":41,"date":"2017-10-27T17:15:13","date_gmt":"2017-10-27T23:15:13","guid":{"rendered":"https:\/\/estatus.io\/blog\/?p=41"},"modified":"2017-10-27T18:04:07","modified_gmt":"2017-10-28T00:04:07","slug":"incident-response-plan","status":"publish","type":"post","link":"https:\/\/estatus.io\/blog\/incident-response-plan\/","title":{"rendered":"The Critical Components Every Incident Response Plan Must Have"},"content":{"rendered":"<p><img loading=\"lazy\" class=\"aligncenter wp-image-47\" src=\"https:\/\/estatus.io\/blog\/wp-content\/uploads\/2017\/10\/timeisnow-min-300x251.jpg\" alt=\"\" width=\"500\" height=\"419\" srcset=\"https:\/\/estatus.io\/blog\/wp-content\/uploads\/2017\/10\/timeisnow-min-300x251.jpg 300w, https:\/\/estatus.io\/blog\/wp-content\/uploads\/2017\/10\/timeisnow-min-768x644.jpg 768w, https:\/\/estatus.io\/blog\/wp-content\/uploads\/2017\/10\/timeisnow-min.jpg 940w\" sizes=\"(max-width: 500px) 100vw, 500px\" \/><\/p>\n<p>Are you ready for the next outage or degradation in performance? \u00a0Do you have your <strong>incident response plan<\/strong> in place? During the last few years, we have witnessed several instances when massive service providers have experienced outages that have cost companies billions.<\/p>\n<p>Let&#8217;s take for instance <a href=\"https:\/\/techcrunch.com\/2017\/02\/28\/amazon-aws-s3-outage-is-breaking-things-for-a-lot-of-websites-and-apps\/\">Amazon\u2019s S3 outage<\/a> earlier this year (February 28, 2017). Some estimate that outage alone, lasting only a few hours, could have cost upwards of $150 million. One single service disruption caused degradations and disruptions to 48 other internal services they have listed on their service health dashboard. One of the lessons to be learned from this event. They host their own status page, which itself was impacted by the outage, resulting in the status indicators not displaying the red outage icon. As a result of not having their page hosted by a third party, it put additional stress on their support team.<\/p>\n<p><img loading=\"lazy\" class=\"aligncenter size-full wp-image-64\" src=\"https:\/\/estatus.io\/blog\/wp-content\/uploads\/2017\/10\/amazon-outage.png\" alt=\"Amazon's outage status page\" width=\"501\" height=\"471\" srcset=\"https:\/\/estatus.io\/blog\/wp-content\/uploads\/2017\/10\/amazon-outage.png 501w, https:\/\/estatus.io\/blog\/wp-content\/uploads\/2017\/10\/amazon-outage-300x282.png 300w\" sizes=\"(max-width: 501px) 100vw, 501px\" \/><\/p>\n<p>This is a continuous risk of modern IT organizations, as we have become dependent on SaaS services. \u00a0The days of hosting your own complex datacenters are over and the future of IT looks to integrate existing services in a meaningful way.<\/p>\n<p>Modern services and applications are typically built on top of a backbone that is hosted offsite and out of the IT organization&#8217;s control. \u00a0These great technological dependencies have created a need for these services to be available 24\/7\/365 and we have seen what can happen when they are not. \u00a0I am willing to bet that you have several services that either partially or solely depends on a third party vendor.<\/p>\n<h1>Who Needs an Incident Response Plan?<\/h1>\n<p>Modern business means that you are providing some sort of IT service to your customers or end users. \u00a0This is consistent no matter the size of your business and the number of your employees you have. \u00a0From the diner on the corner to the tech giant, all businesses are dependent upon IT services.<\/p>\n<p>Let\u2019s think about this for a minute and think about the small diner on the corner. \u00a0There are a lot of logistics behind the scenes for this diner to operate. \u00a0They must have Internet connectivity to order food and supplies. \u00a0They must have an Internet-connected POS system to accept credit card payments (who has cash anymore). \u00a0This POS system is also tracking what was ordered and therefore integrated with an inventory control system.<\/p>\n<p>This diner must be ready for an incident just as much as your tech giant SaaS provider that has millions of clients. \u00a0What will they do when these services fail? \u00a0How will they notify their staff? \u00a0How will they notify their customers? \u00a0What secondary systems are in place in case the first ones fail? \u00a0\u00a0These things can be planned before there are problems and detailed in your incident response plan. \u00a0The time to take action is not when you are in crisis mode, you should be prepared for the day when your systems will fail.<\/p>\n<h2>Incident Response Planning<\/h2>\n<p>The Incident Response planning phase is the most intensive and important aspects of your response plan. \u00a0This is the stage that you are going to lay the foundation and put in all the hard work to develop your plan, process and procedures. This is the kickoff point and is critical to your overall success.<\/p>\n<p>During the planning phase, you should develop training and make sure that all of your staff attends the same training. \u00a0It is important that all of your employees have the same incident response training and are familiar with the various roles that they may fill. \u00a0This is also a good time to plan any drills to test your processes throughout the lifecycle of your plan.<\/p>\n<p>As a matter of practice, you should host bi-annual drills within your organization to prepare your staff for an outage. \u00a0This will ensure that your staff gets an opportunity to experience an outage in the sandbox before the stressful real-world incident. \u00a0Furthermore, spacing these 6 months apart will account for any attrition that you have within your organization and will be a continuation of the onboarding training that your staff should be receiving.<\/p>\n<h2>Incident Response Process &amp; Considerations:<\/h2>\n<h3>What is an incident?<\/h3>\n<p>The popular ITIL framework defines an Incident as an unplanned interruption to an IT Service or reduction in the quality of an IT service. \u00a0This is a broad definition and there are typically other factors that go into your incident response decisions:<\/p>\n<p>Here are some factors that should be considered:<\/p>\n<ul>\n<li>Impact &#8211; How many customers have to be impacted?<\/li>\n<li>Urgency \u2013 What are the effects if the Incident is not resolved in a timely manner?<\/li>\n<li>Time \u2013 How long do you foresee the Incident affecting a service?<\/li>\n<\/ul>\n<h3>Incident Response<\/h3>\n<p>There are many components to your incident response plan and these should include:<\/p>\n<ul>\n<li>Incident Response Roles<\/li>\n<li>Incident Commander<\/li>\n<li>Internal Communication Plan (Staff)<\/li>\n<li>External Communication Plan (Customers)<\/li>\n<li>Time Metrics<\/li>\n<\/ul>\n<h2>Incident Response Roles<\/h2>\n<p><a href=\"https:\/\/estatus.io\/pricing#features-section\"><img loading=\"lazy\" class=\"aligncenter size-full wp-image-43\" src=\"https:\/\/estatus.io\/blog\/wp-content\/uploads\/2017\/10\/incidente-response-roles-min.png\" alt=\"incident response roles infographic\" width=\"800\" height=\"2000\" srcset=\"https:\/\/estatus.io\/blog\/wp-content\/uploads\/2017\/10\/incidente-response-roles-min.png 800w, https:\/\/estatus.io\/blog\/wp-content\/uploads\/2017\/10\/incidente-response-roles-min-120x300.png 120w, https:\/\/estatus.io\/blog\/wp-content\/uploads\/2017\/10\/incidente-response-roles-min-768x1920.png 768w, https:\/\/estatus.io\/blog\/wp-content\/uploads\/2017\/10\/incidente-response-roles-min-410x1024.png 410w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/a><\/p>\n<p>There a many moving parts within your incident response procedures but the role of your staff are most critical to your success. \u00a0The following roles should be considered and applied to your plan:<\/p>\n<ul>\n<li>Incident Commander<\/li>\n<li>Incident Response Team<\/li>\n<li>IT Service Desk<\/li>\n<li>Communications<\/li>\n<li>Management<\/li>\n<\/ul>\n<h3>Incident Commander<\/h3>\n<p>The Incident Commander is responsible for the incident and has several duties throughout the lifecycle of an incident. \u00a0He or she should know what is expected of them during this role and proper proactive training should be given throughout your company. \u00a0Training should not happen during a live incident.<\/p>\n<p>The Incident Commander is in charge of all of the moving pieces and is making sure that everyone is staying on task. \u00a0These duties include but are not limited to:<\/p>\n<ul>\n<li>Resource Assignment<\/li>\n<li>Communication Coordination<\/li>\n<li>Notifications<\/li>\n<li>Documentation (Log activities throughout the event)<\/li>\n<li>Resolution<\/li>\n<li>After action: (Lessons Learned, etc.)<\/li>\n<\/ul>\n<h3>Incident Response Team<\/h3>\n<p>The incident response team is responsible for the identification, troubleshooting and ultimate resolution of your incident. \u00a0These teams can be small or large and will vary between organizations and industry. \u00a0However, the key to having a great incident response team is to make certain that you have enough resources to handle any incident that may arise.<\/p>\n<p><img loading=\"lazy\" class=\"aligncenter size-full wp-image-44\" src=\"https:\/\/estatus.io\/blog\/wp-content\/uploads\/2017\/10\/incident-response-team-min.jpg\" alt=\"Who is on your incident response team?\" width=\"1024\" height=\"512\" srcset=\"https:\/\/estatus.io\/blog\/wp-content\/uploads\/2017\/10\/incident-response-team-min.jpg 1024w, https:\/\/estatus.io\/blog\/wp-content\/uploads\/2017\/10\/incident-response-team-min-300x150.jpg 300w, https:\/\/estatus.io\/blog\/wp-content\/uploads\/2017\/10\/incident-response-team-min-768x384.jpg 768w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/p>\n<p>There are some key positions that should be included on your incident response team:<\/p>\n<ul>\n<li>IT Service Desk<\/li>\n<li>Security Analyst<\/li>\n<li>Developers (Yes- really.)<\/li>\n<li>Database Administrators<\/li>\n<li>Server Administrators<\/li>\n<li>Application Administrators<\/li>\n<li>Network Administrator<\/li>\n<\/ul>\n<h3>IT Service Desk<\/h3>\n<p>Your service desk is your hub and the tip of the iceberg for your organization. \u00a0Typically all of the work that flows through your organization is originated at the service desk. \u00a0This is also the place that users will contact when you are experiencing an outage. \u00a0It is important that your service desk is aware of your outage and any workarounds that have been identified throughout the identification or troubleshooting processes.<\/p>\n<p>I cannot reiterate this enough that you must keep your service desk informed during any outage. \u00a0I have seen the consequences notifying the service desk as an afterthought and it is a recipe for a disorganized chaotic mess. Build this into your plan and make sure you have mechanisms in place to make these critical notifications.<\/p>\n<h3>Communications<\/h3>\n<p><img loading=\"lazy\" class=\"aligncenter wp-image-46 size-full\" src=\"https:\/\/estatus.io\/blog\/wp-content\/uploads\/2017\/10\/redphone-min.png\" alt=\"Is your communication plan outdated graphic\" width=\"801\" height=\"402\" srcset=\"https:\/\/estatus.io\/blog\/wp-content\/uploads\/2017\/10\/redphone-min.png 801w, https:\/\/estatus.io\/blog\/wp-content\/uploads\/2017\/10\/redphone-min-300x151.png 300w, https:\/\/estatus.io\/blog\/wp-content\/uploads\/2017\/10\/redphone-min-768x385.png 768w\" sizes=\"(max-width: 801px) 100vw, 801px\" \/><\/p>\n<p>Communication during an outage is critical to your overall success. \u00a0Too little or too late and you have a herd of angry customers banging down your doors. \u00a0\u00a0Too much communication &#8211; wait that never happens so we can skip that. \u00a0A designated communications representative is imperative to make sure that you are making timely notifications at an acceptable cadence to your customers based upon your incident response plan.<\/p>\n<p>While often a separate role, this role can be shared on within your response team. However, this role should be hyper-focused on internal and external communication and not have to share the burden of troubleshooting, etc. \u00a0To avoid any missteps it is recommended that this resource is free to manage the communications process.<\/p>\n<h3>Management<\/h3>\n<p>Your various team and department management should be available during a problem but should not interfere in the incident response steps the team needs to carry out. There are a lot of critical decisions that may arise during an incident and management should be on hand to aid in these decisions or approve any emergency changes, etc.<\/p>\n<h2>Internal Communication Plan<\/h2>\n<p>During an incident, it is critical to alert your internal support and technical teams. \u00a0These are the people that need to start diagnosing the Incident and moving towards a resolution. \u00a0This is typically the most critical piece of your plan and should involve a solution to notify all of your technical teams and use a swarming technique to address the incident.<\/p>\n<p><img loading=\"lazy\" class=\"aligncenter size-full wp-image-45\" src=\"https:\/\/estatus.io\/blog\/wp-content\/uploads\/2017\/10\/phone2-min.png\" alt=\"We need all system Admins to report for duty graphic\" width=\"802\" height=\"401\" srcset=\"https:\/\/estatus.io\/blog\/wp-content\/uploads\/2017\/10\/phone2-min.png 802w, https:\/\/estatus.io\/blog\/wp-content\/uploads\/2017\/10\/phone2-min-300x150.png 300w, https:\/\/estatus.io\/blog\/wp-content\/uploads\/2017\/10\/phone2-min-768x384.png 768w\" sizes=\"(max-width: 802px) 100vw, 802px\" \/><\/p>\n<p>This swarming technique breaks through the typical IT silos and brings all of your technical experts together to quickly identify root cause and move towards resolution. \u00a0Your technical teams will work collaboratively and not have to worry about a strict chain of command during the identification of root cause. \u00a0This leads to faster root cause identification and ultimate incident resolution.<\/p>\n<h2>External Communication Plan<\/h2>\n<p>The next critical piece of communication is to your customers or end-users and this can take place simultaneously to your internal communication or immediately after. \u00a0This will vary from business to business and other incident impact and urgency factors will go into this determination. \u00a0Find a solution that works for you and your business.<\/p>\n<p>Customers will start flooding your service desk or business phone at the first sign of a problem and this can cost a company millions during major outages. \u00a0In 2017 we should be providing proactive communications to users and avoiding the costly IT phone call to report an issue that we already know is happening. There are several communication methods that may work for your business:<\/p>\n<ul>\n<li>Company Status Page<\/li>\n<li>Email Notifications<\/li>\n<li>SMS Notifications<\/li>\n<li>Message on your support line<\/li>\n<li>Social Media Accounts<\/li>\n<\/ul>\n<p>The goal here is to get the information in front of your customers so that they are informed and so that they are not flooding your IT help desk with costly support calls. \u00a0Furthermore, studies show that proactive notification methods reduce customer stress and instill confidence.<\/p>\n<p>A company status page is how modern organizations communicate with their customers and this will be discussed in greater detail later in this article. \u00a0The comprehensive solutions provide a status page and communication platform that your customers will love. \u00a0Consider your plan before you next outage strikes.<\/p>\n<h2>Time Metrics<\/h2>\n<p>Time metrics are critical to your incident response policy and give you a benchmark for making decisions. \u00a0You should assign time limits to various events and have an action plan to execute once these thresholds have been met or exceeded. \u00a0For example, maybe you have an internal incident triage time of 15 minutes. \u00a0During this initial 15 minutes, your support teams are identifying the problem and trying to get a grasp on the impact. \u00a0At the 15 minutes mark, you should be sending your external communication or activating the necessary communication channels.<\/p>\n<h2>Status Page<\/h2>\n<p>A <a href=\"https:\/\/estatus.io\/pricing#features-section\">status page<\/a> at a basic level is a website that customers can visit to see the status of your applications and services. \u00a0This provides an interception point between a customer detecting a problem and flooding your IT help desk with calls. \u00a0The customer now has a single reference point to check to inquire about the status of your critical services.<\/p>\n<p>Modern status pages are hosted by a third party and provide several features to include email communication, SMS communication, historical data, etc. \u00a0A status page is a great tool to have in your Incident Response Plan and will provide the transparency into your organization that customers expect.<\/p>\n<h2>Conclusion<\/h2>\n<p>SaaS happens everyday and you want to be proactive as opposed to reactive in your Incident Response planning. \u00a0It is critical to provide your staff with a step-by-step guide to aid them in times of crisis. \u00a0The internal process and procedures are the most time consuming and this is where you have to put in a lot of hard work.<\/p>\n<p>Furthermore, IT outages have become very expensive and it is important to restore service as fast as possible. These include providing timely communication and notifications to your customers. \u00a0It is important that your customers have a single point\/place of contact for the status of your services and that they are able to get communications and notifications about the services that are important to them.<\/p>\n<p>Lastly, you have to plan for the unexpected so that when the unexpected happens it is expected. \u00a0This includes documenting your process, procedures and plans. \u00a0You should also train your staff and make sure that everyone within your organization shares the same baseline incident management knowledge. \u00a0Also, it is critical that you stage outage drills to practice your skills and to put your plan through the rigors before the next outage.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Are you ready for the next outage or degradation in performance? \u00a0Do you have your incident response plan in place? During the last few years, we have witnessed several instances when massive service providers have experienced outages that have cost companies billions. Let&#8217;s take for instance Amazon\u2019s S3 outage earlier this year (February 28, 2017).&hellip; <a href=\"https:\/\/estatus.io\/blog\/incident-response-plan\/\" class=\"more-link\">Read more <span class=\"screen-reader-text\">about The Critical Components Every Incident Response Plan Must Have<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":43,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"_genesis_hide_title":false,"_genesis_hide_breadcrumbs":false,"_genesis_hide_singular_image":false,"_genesis_hide_footer_widgets":false,"_genesis_custom_body_class":"","_genesis_custom_post_class":"","_genesis_layout":"centered-content"},"categories":[3],"tags":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v17.3 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>The Critical Components Every Incident Response Plan Must Have<\/title>\n<meta name=\"description\" content=\"If you need to improve or build a new incident response plan, this article is a must read. With so many technological dependencies in the today&#039;s business structure, it is imperative that you become proactive.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/estatus.io\/blog\/incident-response-plan\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"The Critical Components Every Incident Response Plan Must Have\" \/>\n<meta property=\"og:description\" content=\"If you need to improve or build a new incident response plan, this article is a must read. With so many technological dependencies in the today&#039;s business structure, it is imperative that you become proactive.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/estatus.io\/blog\/incident-response-plan\/\" \/>\n<meta property=\"og:site_name\" content=\"estatus.io Blog \u2013 Helping You Navigate The SAAS Landscape\" \/>\n<meta property=\"article:published_time\" content=\"2017-10-27T23:15:13+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2017-10-28T00:04:07+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/estatus.io\/blog\/wp-content\/uploads\/2017\/10\/incidente-response-roles-min.png\" \/>\n\t<meta property=\"og:image:width\" content=\"800\" \/>\n\t<meta property=\"og:image:height\" content=\"2000\" \/>\n<meta name=\"twitter:card\" content=\"summary\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Jesse Schwarz\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"10 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Organization\",\"@id\":\"https:\/\/estatus.io\/blog\/#organization\",\"name\":\"eStatus.io\",\"url\":\"https:\/\/estatus.io\/blog\/\",\"sameAs\":[],\"logo\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/estatus.io\/blog\/#logo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/estatus.io\/blog\/wp-content\/uploads\/2017\/10\/estatus-2.png\",\"contentUrl\":\"https:\/\/estatus.io\/blog\/wp-content\/uploads\/2017\/10\/estatus-2.png\",\"width\":393,\"height\":60,\"caption\":\"eStatus.io\"},\"image\":{\"@id\":\"https:\/\/estatus.io\/blog\/#logo\"}},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/estatus.io\/blog\/#website\",\"url\":\"https:\/\/estatus.io\/blog\/\",\"name\":\"estatus.io Blog \\u2013 Helping You Navigate The SAAS Landscape\",\"description\":\"You will find carefully researched and professionally written SAAS related whitepapers and articles that will help you navigate the complex business environment we live in. From status page guides to incident response plans, we strive to become a leading resource in the SAAS landscape.\",\"publisher\":{\"@id\":\"https:\/\/estatus.io\/blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/estatus.io\/blog\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/estatus.io\/blog\/incident-response-plan\/#primaryimage\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/estatus.io\/blog\/wp-content\/uploads\/2017\/10\/incidente-response-roles-min.png\",\"contentUrl\":\"https:\/\/estatus.io\/blog\/wp-content\/uploads\/2017\/10\/incidente-response-roles-min.png\",\"width\":800,\"height\":2000,\"caption\":\"incident response roles infographic\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/estatus.io\/blog\/incident-response-plan\/#webpage\",\"url\":\"https:\/\/estatus.io\/blog\/incident-response-plan\/\",\"name\":\"The Critical Components Every Incident Response Plan Must Have\",\"isPartOf\":{\"@id\":\"https:\/\/estatus.io\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/estatus.io\/blog\/incident-response-plan\/#primaryimage\"},\"datePublished\":\"2017-10-27T23:15:13+00:00\",\"dateModified\":\"2017-10-28T00:04:07+00:00\",\"description\":\"If you need to improve or build a new incident response plan, this article is a must read. With so many technological dependencies in the today's business structure, it is imperative that you become proactive.\",\"breadcrumb\":{\"@id\":\"https:\/\/estatus.io\/blog\/incident-response-plan\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/estatus.io\/blog\/incident-response-plan\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/estatus.io\/blog\/incident-response-plan\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/estatus.io\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"The Critical Components Every Incident Response Plan Must Have\"}]},{\"@type\":\"Article\",\"@id\":\"https:\/\/estatus.io\/blog\/incident-response-plan\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/estatus.io\/blog\/incident-response-plan\/#webpage\"},\"author\":{\"@id\":\"https:\/\/estatus.io\/blog\/#\/schema\/person\/7c9b97bca7c78dabcafd9b3d2497fcd8\"},\"headline\":\"The Critical Components Every Incident Response Plan Must Have\",\"datePublished\":\"2017-10-27T23:15:13+00:00\",\"dateModified\":\"2017-10-28T00:04:07+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/estatus.io\/blog\/incident-response-plan\/#webpage\"},\"wordCount\":2104,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/estatus.io\/blog\/#organization\"},\"image\":{\"@id\":\"https:\/\/estatus.io\/blog\/incident-response-plan\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/estatus.io\/blog\/wp-content\/uploads\/2017\/10\/incidente-response-roles-min.png\",\"articleSection\":[\"Incident Response Planning\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/estatus.io\/blog\/incident-response-plan\/#respond\"]}]},{\"@type\":\"Person\",\"@id\":\"https:\/\/estatus.io\/blog\/#\/schema\/person\/7c9b97bca7c78dabcafd9b3d2497fcd8\",\"name\":\"Jesse Schwarz\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/estatus.io\/blog\/#personlogo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/022ed24face656efa732c112bca3c816?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/022ed24face656efa732c112bca3c816?s=96&d=mm&r=g\",\"caption\":\"Jesse Schwarz\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"The Critical Components Every Incident Response Plan Must Have","description":"If you need to improve or build a new incident response plan, this article is a must read. With so many technological dependencies in the today's business structure, it is imperative that you become proactive.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/estatus.io\/blog\/incident-response-plan\/","og_locale":"en_US","og_type":"article","og_title":"The Critical Components Every Incident Response Plan Must Have","og_description":"If you need to improve or build a new incident response plan, this article is a must read. With so many technological dependencies in the today's business structure, it is imperative that you become proactive.","og_url":"https:\/\/estatus.io\/blog\/incident-response-plan\/","og_site_name":"estatus.io Blog \u2013 Helping You Navigate The SAAS Landscape","article_published_time":"2017-10-27T23:15:13+00:00","article_modified_time":"2017-10-28T00:04:07+00:00","og_image":[{"width":800,"height":2000,"url":"https:\/\/estatus.io\/blog\/wp-content\/uploads\/2017\/10\/incidente-response-roles-min.png","type":"image\/png"}],"twitter_card":"summary","twitter_misc":{"Written by":"Jesse Schwarz","Est. reading time":"10 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Organization","@id":"https:\/\/estatus.io\/blog\/#organization","name":"eStatus.io","url":"https:\/\/estatus.io\/blog\/","sameAs":[],"logo":{"@type":"ImageObject","@id":"https:\/\/estatus.io\/blog\/#logo","inLanguage":"en-US","url":"https:\/\/estatus.io\/blog\/wp-content\/uploads\/2017\/10\/estatus-2.png","contentUrl":"https:\/\/estatus.io\/blog\/wp-content\/uploads\/2017\/10\/estatus-2.png","width":393,"height":60,"caption":"eStatus.io"},"image":{"@id":"https:\/\/estatus.io\/blog\/#logo"}},{"@type":"WebSite","@id":"https:\/\/estatus.io\/blog\/#website","url":"https:\/\/estatus.io\/blog\/","name":"estatus.io Blog \u2013 Helping You Navigate The SAAS Landscape","description":"You will find carefully researched and professionally written SAAS related whitepapers and articles that will help you navigate the complex business environment we live in. From status page guides to incident response plans, we strive to become a leading resource in the SAAS landscape.","publisher":{"@id":"https:\/\/estatus.io\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/estatus.io\/blog\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"ImageObject","@id":"https:\/\/estatus.io\/blog\/incident-response-plan\/#primaryimage","inLanguage":"en-US","url":"https:\/\/estatus.io\/blog\/wp-content\/uploads\/2017\/10\/incidente-response-roles-min.png","contentUrl":"https:\/\/estatus.io\/blog\/wp-content\/uploads\/2017\/10\/incidente-response-roles-min.png","width":800,"height":2000,"caption":"incident response roles infographic"},{"@type":"WebPage","@id":"https:\/\/estatus.io\/blog\/incident-response-plan\/#webpage","url":"https:\/\/estatus.io\/blog\/incident-response-plan\/","name":"The Critical Components Every Incident Response Plan Must Have","isPartOf":{"@id":"https:\/\/estatus.io\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/estatus.io\/blog\/incident-response-plan\/#primaryimage"},"datePublished":"2017-10-27T23:15:13+00:00","dateModified":"2017-10-28T00:04:07+00:00","description":"If you need to improve or build a new incident response plan, this article is a must read. With so many technological dependencies in the today's business structure, it is imperative that you become proactive.","breadcrumb":{"@id":"https:\/\/estatus.io\/blog\/incident-response-plan\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/estatus.io\/blog\/incident-response-plan\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/estatus.io\/blog\/incident-response-plan\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/estatus.io\/blog\/"},{"@type":"ListItem","position":2,"name":"The Critical Components Every Incident Response Plan Must Have"}]},{"@type":"Article","@id":"https:\/\/estatus.io\/blog\/incident-response-plan\/#article","isPartOf":{"@id":"https:\/\/estatus.io\/blog\/incident-response-plan\/#webpage"},"author":{"@id":"https:\/\/estatus.io\/blog\/#\/schema\/person\/7c9b97bca7c78dabcafd9b3d2497fcd8"},"headline":"The Critical Components Every Incident Response Plan Must Have","datePublished":"2017-10-27T23:15:13+00:00","dateModified":"2017-10-28T00:04:07+00:00","mainEntityOfPage":{"@id":"https:\/\/estatus.io\/blog\/incident-response-plan\/#webpage"},"wordCount":2104,"commentCount":0,"publisher":{"@id":"https:\/\/estatus.io\/blog\/#organization"},"image":{"@id":"https:\/\/estatus.io\/blog\/incident-response-plan\/#primaryimage"},"thumbnailUrl":"https:\/\/estatus.io\/blog\/wp-content\/uploads\/2017\/10\/incidente-response-roles-min.png","articleSection":["Incident Response Planning"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/estatus.io\/blog\/incident-response-plan\/#respond"]}]},{"@type":"Person","@id":"https:\/\/estatus.io\/blog\/#\/schema\/person\/7c9b97bca7c78dabcafd9b3d2497fcd8","name":"Jesse Schwarz","image":{"@type":"ImageObject","@id":"https:\/\/estatus.io\/blog\/#personlogo","inLanguage":"en-US","url":"https:\/\/secure.gravatar.com\/avatar\/022ed24face656efa732c112bca3c816?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/022ed24face656efa732c112bca3c816?s=96&d=mm&r=g","caption":"Jesse Schwarz"}}]}},"_links":{"self":[{"href":"https:\/\/estatus.io\/blog\/wp-json\/wp\/v2\/posts\/41"}],"collection":[{"href":"https:\/\/estatus.io\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/estatus.io\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/estatus.io\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/estatus.io\/blog\/wp-json\/wp\/v2\/comments?post=41"}],"version-history":[{"count":11,"href":"https:\/\/estatus.io\/blog\/wp-json\/wp\/v2\/posts\/41\/revisions"}],"predecessor-version":[{"id":65,"href":"https:\/\/estatus.io\/blog\/wp-json\/wp\/v2\/posts\/41\/revisions\/65"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/estatus.io\/blog\/wp-json\/wp\/v2\/media\/43"}],"wp:attachment":[{"href":"https:\/\/estatus.io\/blog\/wp-json\/wp\/v2\/media?parent=41"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/estatus.io\/blog\/wp-json\/wp\/v2\/categories?post=41"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/estatus.io\/blog\/wp-json\/wp\/v2\/tags?post=41"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}