SOC 2 Type II
Security

Incident Response Plan Template

Structured approach for detecting, responding to, and recovering from security incidents.

What This Policy Covers

Purpose and Scope-Plan objectives.
Incident Classification-Severity levels P1-P4.
Incident Response Team-Team roles and contacts.
Detection and Identification-How incidents are detected.
Containment Strategy-Containment procedures.
Eradication and Recovery-Removing threats and restoring.
Communication Plan-Internal and external comms.
Escalation Matrix-Escalation procedures.
Post-Incident Review-Lessons learned.
Plan Testing-Tabletop exercises.

Required Sections

A compliant Incident Response Plan for SOC 2 Type II must include the following10 sections. Each section addresses a specific control requirement that auditors will review.

1

Purpose and Scope

Plan objectives.

2

Incident Classification

Severity levels P1-P4.

3

Incident Response Team

Team roles and contacts.

4

Detection and Identification

How incidents are detected.

5

Containment Strategy

Containment procedures.

6

Eradication and Recovery

Removing threats and restoring.

7

Communication Plan

Internal and external comms.

8

Escalation Matrix

Escalation procedures.

9

Post-Incident Review

Lessons learned.

10

Plan Testing

Tabletop exercises.

Generate a Customized Version

This template shows the required structure. PoliWriter generates a fully customized Incident Response Plan that references your actual cloud providers, identity systems, tools, and team practices — ready for auditor review.