Skip to main content
MuonPartners
Services
Architecture

Solution design and technology roadmapping

Solution AssessmentTechnology RoadmapsIntegration DesignSolution ArchitectureTechnical Design
Cyber Security

Security assessments, IAM, and compliance

AssessmentsIAMComplianceSecurity BaselineCyber Innovation
Network and Platform

Network architecture and cloud platforms

Network DesignCloud StrategyModernisation
Enterprise Architecture

Business-technology alignment

Business AlignmentPortfolio AnalysisGovernance
View all services
ProjectsCase StudiesInsightsToolsAbout
Contact Us

Services

Architecture
Solution AssessmentTechnology RoadmapsIntegration DesignSolution ArchitectureTechnical Design
Cyber Security
AssessmentsIAMComplianceSecurity BaselineCyber Innovation
Network and Platform
Network DesignCloud StrategyModernisation
Enterprise Architecture
Business AlignmentPortfolio AnalysisGovernance
ProjectsCase StudiesInsightsToolsAboutContact
Get in Touch
MuonPartners

Strategic technology consulting for Australian organisations navigating complexity.

Services

  • Architecture
  • Cyber Security
  • Network and Platform
  • Enterprise Architecture

Company

  • About
  • Products
  • Frameworks
  • Cross-Framework Mapping
  • Projects
  • Case Studies
  • Insights
  • Contact

Contact

  • [email protected]
  • Australia
  • LinkedIn

© 2026 Muon Partners. All rights reserved.

ABN 50 669 022 315 · A Muon Group company.

Privacy PolicyTerms of Service
  1. Frameworks
  2. >ISM
  3. >Cyber Security Documentation
  4. >System-Specific Cyber Security Documentation
  5. >Cyber Security Incident Response Plan
  6. >ISM-0043
ISM-0043Active

Control: ism-0043

Control Statement

Systems have a cyber security incident response plan that covers the following:

  • guidelines on what constitutes a cyber security incident
  • the types of cyber security incidents likely to be encountered and the expected response to each type
  • how to report cyber security incidents, internally to an organisation and externally to relevant authorities
  • other parties which need to be informed in the event of a cyber security incident
  • the authority, or authorities, responsible for investigating and responding to cyber security incidents
  • the criteria by which an investigation of a cyber security incident would be requested from a law enforcement agency, the Australian Signals Directorate or other relevant authority
  • the steps necessary to ensure the integrity of evidence relating to a cyber security incident
  • system contingency measures or a reference to such details if they are located in a separate document.

Location

Guideline
Guidelines for cyber security documentation
Section
System-specific cyber security documentation
Topic
Cyber security incident response plan

Control Details

Identifier
ISM-0043
Revision
5
Updated
Sep-23
Type
Control

Classification Applicability

NCOSPSTS

Essential Eight

N/A
AESCSF
AESCSF-PRIVACY-1Mrelatedvia aescsf-reference
AESCSF-RESPONSE-1arelatedvia aescsf-reference
AESCSF-RESPONSE-2arelatedvia aescsf-reference
AESCSF-RESPONSE-2crelatedvia aescsf-reference
AESCSF-RESPONSE-2drelatedvia aescsf-reference
View in graphReport an issue
← Back to Cyber security incident response plan