RESPONDER RESOURCES
Working artifacts for the incident
Small, editable templates designed to capture evidence and decisions while the response is moving. Adapt fields, authorities, retention, and legal requirements before an incident.
Download and adapt
These files intentionally contain no automation, macros, remote content, or third-party JavaScript. Do not place secret values in the credential register.
Incident timeline
Record authoritative UTC events, sources, confidence, decisions, and owners.
Download CSV ↓CSV / EDITABLE TEMPLATEEvidence inventory
Track collection source, integrity, custody, access, retention, and storage.
Download CSV ↓MD / EDITABLE TEMPLATEContainment decision record
Document alternatives, operational impact, evidence, approval, and rollback.
Download MD ↓CSV / EDITABLE TEMPLATECredential rotation register
Coordinate revocation and replacement without recording secret values.
Download CSV ↓YAML / EDITABLE TEMPLATEAI runtime snapshot
Preserve model, prompt, agent, identity, retrieval, policy, tool, and trace state.
Download YAML ↓MD / EDITABLE TEMPLATERecovery authorization
Require security and service evidence, monitoring, staged restoration, and rollback ownership.
Download MD ↓Use them safely
- Assign an owner and authoritative UTC time source before collection begins.
- Store incident records in a protected repository with least privilege, retention, and access logging.
- Record references to secrets and credentials—never plaintext secret values.
- Hash evidence exports where integrity or chain of custody matters.
- Have legal, privacy, safety, regulatory, and business owners approve organization-specific fields.
- Test every template during a tabletop and revise it when responders cannot use it under pressure.