CAIQ v4
Control SEF-01
Extractive Review Standard
How to answer 'Do you have a documented Security Incident Response Plan (IRP) with designated roles?' on a CAIQ
Reviewer Guidance & Pitfalls
Outline the phases of your IRP (Preparation, Detection, Containment, Eradication, Recovery, Post-Mortem) and designate incident commander and communications roles.
Example Answer Passing Enterprise Audit
Compliant Response Template
Yes. We maintain a formal Security Incident Response Plan outlining on-call incident commanders, triage workflows, containment protocols, and customer notification procedures (SOC 2, CC7.3).
Filling out a CAIQ or SIG Lite right now?
QuietQuestionnaire automatically drafts answers with citations from your own SOC 2 report, catches contradictions reviewers reject, and locks exports behind cryptographic human sign-off.
Zero spam. 100% confidential. No credit card required.