Free policy template ISO 27001

Incident Response & Breach Notification Policy

The defined channel, triage, response, and notification steps for security events, so nothing is improvised under pressure.

Download the Markdown

Free and ungated, no email required. The full template is below and in the download. Authored in Keel's own words and mapped to ISO 27001 by clause; replace the {{PLACEHOLDER}} tokens with your details.

How to use it

  1. Download the template. Grab the Markdown file, or copy the full text from this page.
  2. Fill in the placeholders. Replace every {{PLACEHOLDER}} token (company name, owner, approver, dates, version) with your details.
  3. Tailor it to how you operate. Adjust the statements so they describe what your organization actually does. A policy you do not follow is worse than none.
  4. Approve and publish. Have an accountable owner approve it, set an effective date and a review date, and share it where staff can find it.
  5. Keep it current. Review on the schedule you set (or when things change), and keep evidence that it is followed. In Keel this is tracked for you.

Related

Incident Response & Breach Notification

Organization: {{COMPANY_LEGAL_NAME}} Document owner: {{POLICY_OWNER_ROLE}} Approved by: {{APPROVER_NAME}}, {{APPROVER_TITLE}} Version: {{VERSION}} · Effective: {{EFFECTIVE_DATE}} · Next review: {{REVIEW_DATE}} Classification: Internal


1. Purpose

This policy makes sure security and privacy incidents at {{COMPANY_LEGAL_NAME}} are found, contained, reported, and resolved quickly, and that any required notifications go out on time and through the right people.

2. Scope

This policy covers all information assets, personnel, third-party services, and physical locations, including systems in {{CRITICAL_SYSTEMS}} and records held across {{GEO_SCOPE}}.

3. Policy statements

3.1 Detection and reporting

Security tooling forwards alerts to a dedicated incident channel in real time. Anyone who notices suspicious activity reports it to the security team promptly, and every alert or report is logged in the incident tracker with a timestamp.

3.2 Response team and roles

Each incident has an Incident Commander, a Technical Lead, a Communications Lead, and a Scribe, backed by a published roster with around-the-clock contacts. We keep runbooks for common scenarios such as malware, data breach, denial-of-service, and cloud compromise.

3.3 Containment and eradication

We isolate affected systems quickly once an incident is confirmed, capture forensic evidence where feasible, and patch, clean, or rebuild before anything is reconnected. Actions and timestamps are documented in the tracker.

3.4 Breach notification and communications

Management is notified immediately for incidents involving personal or regulated data. Customer and regulator notices are drafted within the applicable legal timeframes, and all external statements are routed through the Communications Lead and legal counsel before they go out.

3.5 Post-incident review

We hold a root-cause review shortly after each significant incident and record corrective actions, owners, and due dates. Those actions are tracked to closure, and confirmed improvements are folded back into our controls.

3.6 Measurement

We track how long it takes to detect and to contain incidents, along with whether notification deadlines were met, and review these figures regularly. Process deviations are acceptable only when needed to protect life, safety, or critical systems, and are documented afterward.

4. Roles and responsibilities

Role Responsibility
Executive sponsor Accountable for the program; approves this policy
{{POLICY_OWNER_ROLE}} Maintains this policy and its procedures
Managers Enforce the policy within their teams
All personnel Comply; report issues promptly

5. Compliance and exceptions

Unreported or mishandled incidents escalate to executive review and may result in disciplinary action. Exceptions require documented risk acceptance by {{APPROVER_TITLE}} and are time-limited and reviewed.

6. Review

This policy is reviewed at least annually and when significant change occurs.


Aligned to ISO/IEC 27001:2022. {{COMPANY_LEGAL_NAME}} is not affiliated with or endorsed by the relevant standards body; full standard text is copyrighted and is not reproduced here.

This template is authored by Keel in its own words. Clause references to ISO 27001 are factual identifiers; Keel is not affiliated with or endorsed by the standards bodies named. It is a starting point, not legal advice, review and adapt it for your organization.

Manage this policy in Keel

Keel ships this template in-product, fills the placeholders, maps it to your controls, and tracks approvals and reviews, so the policy stays live evidence, not a file in a drive. Start free.

Start free Browse all templates