incident-plan

Create an incident response program aligned with NIST SP 800-61r2.

13|3|Updated Mar 27, 2026
One-click install
npx skills add https://github.com/heaptracetechnology/heaptrace-skills --skill incident-plan
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: incident-plan
Source: https://github.com/heaptracetechnology/heaptrace-skills/tree/main/compliance/incident-plan
Command: npx skills add https://github.com/heaptracetechnology/heaptrace-skills --skill incident-plan

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Incident Response Plan provides a complete, production-ready blueprint that enables teams to prepare, detect, contain, eradicate, recover, and review incidents in a manner aligned with NIST SP 800-61r2 and regulatory breach-notification timelines.

Core Features & Use Cases

  • End-to-end lifecycle coverage: maps each activity to the NIST phases (preparation, detection/analysis, containment-eradication-recovery, and post-incident activity) including templates and checklists.
  • Regulatory alignment: documents breach-notification timelines for GDPR, HIPAA, SEC, and state laws, with communication and evidence-preservation templates.
  • Tabletop readiness: provides runbooks, templates, and guidance to conduct blameless post-mortems and continuous improvement.

Quick Start

Customize this plan for your environment and run a tabletop exercise to validate roles, runbooks, and notification workflows.

Frequently Asked Questions about incident-plan

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I build an incident response plan aligned with NIST SP 800-61r2?▼

An incident response plan aligned with NIST SP 800-61r2 maps activities across preparation, detection, containment, eradication, recovery, and post-incident phases. This plan provides templates and checklists to structure each lifecycle step for your environment.

What are the breach notification timelines for HIPAA, GDPR, and SEC incidents?▼

Breach notification timelines for HIPAA, GDPR, and SEC require strict deadlines for regulatory reporting. This plan documents these specific timelines alongside communication templates and evidence-preservation guidelines to ensure compliance.

How do I conduct a tabletop exercise for incident response?▼

To conduct a tabletop exercise for incident response, customize your plan for the environment and validate roles, runbooks, and notification workflows. This plan provides runbooks and templates to test pre-breach planning and response readiness.

What should be included in a blameless post-mortem after a security incident?▼

A blameless post-mortem after a security incident should include structured review activities and continuous improvement guidance. This plan supplies templates for post-incident analysis to evaluate detection, containment, and recovery actions.

Does this incident response program support governance and evidence handling?▼

Yes, this incident response program specifies governance roles, testing cadence, and evidence handling procedures. It details communication templates and notification workflows to support compliance and incident response teams.

Can I use this plan for pre-breach planning and regulatory audits?▼

Yes, you can use this plan for pre-breach planning and regulatory audits. It applies the NIST lifecycle to test readiness across HIPAA, GDPR, and SEC requirements through tabletop exercises and documented breach-notification workflows.