1. Purpose & Scope
-
Purpose: Describe the objective of this SOP (e.g., to ensure consistent and compliant execution of [process/policy] during incident response).
-
Scope: Define the systems, teams, business units, or processes this SOP applies to.
2. Definitions
- List and define key terms, acronyms, or concepts relevant to this SOP (e.g., escalation, containment, severity levels).
3. Roles & Responsibilities
-
Role 1: [e.g., Incident Commander] Responsibilities: [List responsibilities]
-
Role 2: [e.g., Communications Lead] Responsibilities: [List responsibilities]
-
Other Roles: [List additional roles and their responsibilities]
4. Procedure
4.1 Prerequisites
- List required access, permissions, tools, or conditions needed before executing this SOP.
4.2 Step-by-Step Instructions
- Describe the first action
- Describe the next action
- Continue as needed
- ...
- For detailed technical steps, reference relevant runbooks or KB articles.
5. Compliance & Auditability
- Outline how compliance with this SOP is ensured (e.g., logging, documentation, periodic review).
- Specify audit requirements or checkpoints.
6. Communication & Escalation
-
Internal Communication: [Describe how and when to communicate with internal stakeholders]
-
Escalation Criteria: [Define when and how to escalate issues or deviations from the SOP]
7. References & Linked Resources
-
Runbooks: [Link to technical runbooks for specific steps]
-
Playbooks: [Link to relevant playbooks for scenario context]
-
Knowledge Base Articles: [Link to supporting KB articles, troubleshooting guides, or PIRs]
-
Other SOPs: [Link to related SOPs]
8. Appendices
-
Contact List: [Key personnel and escalation contacts]
-
Templates & Forms: [Incident log, communication templates, evidence collection forms]
-
Process Flowchart: [Visual diagram of the SOP workflow, if applicable]
9. Review & Maintenance
-
Review Cycle: [Specify frequency and triggers for review]
-
Feedback Process: [Describe how feedback is collected and incorporated]
Naming Convention
- Format:
SOP-###-XXXSOP= Standard Operating Procedure###= Unique three-digit identifierXXX= Short process or policy code
- Example:
SOP-003-ENGAGECENG
Tips for Use:
- Ensure all actions are logged for audit and review.
- Reference runbooks for detailed technical steps.
- Regularly review and update the SOP to reflect lessons learned and changes in systems or processes.
- Maintain bidirectional links with related runbooks, playbooks, and KB articles for seamless navigation.
Contributor
Firstname Lastname
GitHub: https://github.com/account
Contributed to the Arcana Incident Response Documentation Framework.
