# Incident Response Readiness Checklist

## People and authority
- [ ] Incident lead and alternates are named
- [ ] Severity and escalation criteria are documented
- [ ] Executive, legal, communications, and business contacts are current
- [ ] Authority for containment actions is understood

## Technical readiness
- [ ] Emergency access to identity, endpoint, network, cloud, and logging systems is tested
- [ ] Evidence retention and export procedures are known
- [ ] Responders can isolate accounts, hosts, applications, and network paths
- [ ] Backup and recovery dependencies are understood

## Communications and decisions
- [ ] Out-of-band communication is available
- [ ] Internal and external notification paths are documented
- [ ] High-impact decision points have defined owners
- [ ] The plan has been exercised in the last 12 months
