incident-plan

Create an incident response program aligned with NIST SP 800-61r2.

13|3|Updated Mar 27, 2026
One-click install
npx skills add https://github.com/heaptracetechnology/heaptrace-skills --skill incident-plan
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: incident-plan
Source: https://github.com/heaptracetechnology/heaptrace-skills/tree/main/compliance/incident-plan
Command: npx skills add https://github.com/heaptracetechnology/heaptrace-skills --skill incident-plan

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Incident Response Plan provides a complete, production-ready blueprint that enables teams to prepare, detect, contain, eradicate, recover, and review incidents in a manner aligned with NIST SP 800-61r2 and regulatory breach-notification timelines.

Core Features & Use Cases

  • End-to-end lifecycle coverage: maps each activity to the NIST phases (preparation, detection/analysis, containment-eradication-recovery, and post-incident activity) including templates and checklists.
  • Regulatory alignment: documents breach-notification timelines for GDPR, HIPAA, SEC, and state laws, with communication and evidence-preservation templates.
  • Tabletop readiness: provides runbooks, templates, and guidance to conduct blameless post-mortems and continuous improvement.

Quick Start

Customize this plan for your environment and run a tabletop exercise to validate roles, runbooks, and notification workflows.

Frequently Asked Questions about incident-plan

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I build an incident response plan aligned with NIST SP 800-61r2?

An incident response plan aligned with NIST SP 800-61r2 maps activities across preparation, detection, containment, eradication, recovery, and post-incident phases. This plan provides templates and checklists to structure each lifecycle step for your environment.

What are the breach notification timelines for HIPAA, GDPR, and SEC incidents?

Breach notification timelines for HIPAA, GDPR, and SEC require strict deadlines for regulatory reporting. This plan documents these specific timelines alongside communication templates and evidence-preservation guidelines to ensure compliance.

How do I conduct a tabletop exercise for incident response?

To conduct a tabletop exercise for incident response, customize your plan for the environment and validate roles, runbooks, and notification workflows. This plan provides runbooks and templates to test pre-breach planning and response readiness.

What should be included in a blameless post-mortem after a security incident?

A blameless post-mortem after a security incident should include structured review activities and continuous improvement guidance. This plan supplies templates for post-incident analysis to evaluate detection, containment, and recovery actions.

Does this incident response program support governance and evidence handling?

Yes, this incident response program specifies governance roles, testing cadence, and evidence handling procedures. It details communication templates and notification workflows to support compliance and incident response teams.

Can I use this plan for pre-breach planning and regulatory audits?

Yes, you can use this plan for pre-breach planning and regulatory audits. It applies the NIST lifecycle to test readiness across HIPAA, GDPR, and SEC requirements through tabletop exercises and documented breach-notification workflows.