A security incident rarely follows the response plan exactly as it was written.Â
Table of Contents
An unusual login may turn out to be a false alarm. It could also be the first sign that an attacker has gained access to an employee account and is moving through the environment.Â
Once an incident is confirmed, the security team must simultaneously understand what happened, contain the threat, preserve relevant evidence and determine whether the incident creates any regulatory, contractual or reporting obligations.Â
This is where incident response compliance becomes important.Â
The requirements can vary considerably between organisations. They depend on where the organisation operates, the type of information it handles, the services it provides and the regulatory or assurance frameworks that apply to its business.Â
For example, organisations operating in India may need to consider CERT-In requirements and the Digital Personal Data Protection (DPDP) Act, 2023. Organisations that process personal data within the scope of GDPR may need to consider its breach requirements. ISO/IEC 27035 provides specific guidance for information security incident management, while SOC 2 focuses on controls relevant to areas such as security, availability, confidentiality and privacy.Â
The important point is that incident response should account for the requirements that actually apply to the organisation.Â
Key TakeawaysÂ
- Incident response compliance means aligning detection, investigation, containment, and reporting with the regulatory, contractual, and security requirements that apply to an organisation.Â
- Not every security incident triggers a mandatory notification -- the obligation depends on what the investigation confirms was affected.Â
- CERT-In requires specified cyber incidents to be reported within six hours; GDPR requires qualifying personal data breaches to be reported within 72 hours where feasible.Â
- ISO/IEC 27035 provides the incident-management lifecycle, while SOC 2 assesses whether related controls are operating effectively -- neither replaces the other.Â
- Incident response plans need regular testing, reliable logging, and clear coordination between security, privacy, legal, and compliance teams to remain effective.Â
What Is Incident Response Compliance?
Incident response compliance means managing and documenting security incidents in line with the regulatory, contractual, and security requirements that apply to an organisation, built into detection, investigation, containment, and reporting rather than treated as a separate exercise.Â
It is part of the wider process of preparing for, investigating and managing security incidents while meeting applicable regulatory, contractual and security requirements.Â
A typical incident response process may involve:Â
The process will vary depending on the nature and severity of the incident. This lifecycle mirrors the structure used in established models such as NIST SP 800-61 and the SANS PICERL framework.Â
A suspicious login may require a relatively straightforward investigation. A compromised privileged account could require the security team to review identity activity, endpoint data, network traffic, application logs and access records before determining the extent of the compromise.Â
Preparation therefore matters.Â
Before an incident occurs, organisations should know who is responsible for leading the investigation, who needs to be informed, how evidence will be collected, when an incident needs to be escalated and which teams are responsible for assessing regulatory or contractual obligations.Â
When Does a Security Incident Become a Compliance Issue?
A security incident becomes a compliance issue once an investigation confirms what was affected and whether that triggers a regulatory, contractual, or reporting obligation.Â
The organisation first needs to understand what happened and what was affected.Â
During an investigation, the team may need to establish:Â
- Which systems, accounts or applications were affected? Â
- Was personal or sensitive information involved? Â
- When did the activity begin? Â
- When was it discovered? Â
- Was information accessed, modified or removed? Â
- What evidence needs to be preserved? Â
- Which regulatory or contractual requirements apply? Â
- Who needs to be involved in the decision? Â
The answers can change the response significantly.Â
For example, an employee account compromise may initially appear to be an access-control issue. If the investigation shows that the account was used to access personal data, the incident may also have data-protection implications.Â
This is why incident response often requires coordination between the SOC or IT team and other functions such as privacy, legal, compliance, communications and business teams.Â
The security team provides the technical facts. The relevant stakeholders can then use those facts to determine the appropriate next steps.Â
Which Regulations and Frameworks Are Relevant to Incident Response?
Several regulations and frameworks can apply to incident response depending on where an organisation operates and the type of data it handles, including CERT-In, the DPDP Act, GDPR, ISO/IEC 27035, SOC 2, and NIST SP 800-61.Â
Different regulations and frameworks address different requirements.Â
| Regulation / Framework | Geographic or business context | Relevance to incident response |
| CERT-In | India | Cyber incident reporting and related cybersecurity requirements |
| DPDP Act, 2023 | India | Protection of digital personal data and personal data breach obligations |
| GDPR | EU and organisations within its scope | Personal data breach assessment and notification |
| ISO/IEC 27035 | International | Information security incident management |
| SOC 2 | Organisations subject to SOC 2 assurance requirements | Demonstrating that relevant controls operate effectively |
| NIST SP 800-61 | International | General computer security incident handling lifecycle and guidance |
The organisation first needs to determine which requirements apply to its environment. Organisations in regulated sectors such as banking, securities, or insurance may also need to account for directions issued by sectoral regulators such as the RBI, SEBI, or IRDAI.Â
The purpose of incident response is then to incorporate those requirements into the operational process rather than treating compliance as a separate exercise.Â
What Are CERT-In's Incident Response Requirements in India?
For organisations operating in India, CERT-In is an important consideration when developing an incident response process.Â
Under directions issued under Section 70B of the Information Technology Act, 2000, CERT-In has established requirements relating to cybersecurity practices, prevention, response and reporting of specified cyber incidents.Â
What is the CERT-In incident reporting timeline?
Specified cyber incidents must be reported to CERT-In within six hours of noticing the incident or being brought to notice, in accordance with the applicable directions.Â
- Reporting timeline: within six hours of detectionÂ
- Legal basis: Directions issued under Section 70B, Information Technology Act, 2000Â
- Scope: specified cyber incidents, including data breaches, unauthorised access, and ransomware attacksÂ
This makes the early stages of incident response particularly important.Â
An organisation needs to establish the basic facts quickly, preserve relevant information and involve the appropriate stakeholders. The investigation may continue as additional information becomes available, but the response process cannot simply wait until every detail is known.Â
CERT-In requirements also make areas such as incident analysis, communication, coordination, reporting and record retention important parts of an organisation's incident response capability.Â
For a more detailed explanation, see Eventus'Â CERT-In Compliance in India.Â
Official reference:Â CERT-In Directions under Section 70BÂ
How Does the DPDP Act Affect Incident Response in India?
The Digital Personal Data Protection Act, 2023 (DPDP Act) is another consideration for organisations operating in India when an incident involves digital personal data. Under the DPDP Act, a Data Fiduciary must notify the Data Protection Board of India and the affected Data Principals when a personal data breach occurs.Â
CERT-In and the DPDP Act address different areas.Â
CERT-In focuses on specified cybersecurity incidents and related reporting and security requirements, while the DPDP Act addresses the protection and processing of digital personal data.Â
An incident may therefore require an organisation to consider both sets of obligations, depending on the circumstances.Â
This also highlights why incident response cannot sit entirely within the security team. Where personal data may be involved, security teams may need to work with privacy, legal and compliance stakeholders to assess the incident and determine the appropriate response.Â
For organisations reviewing their readiness, Eventus DPDPA Compliance Checklist covers areas including security safeguards, breach response, governance and compliance readiness.Â
How Does GDPR Apply to Personal Data Breach Response?
GDPR applies to organisations within its scope, including certain organisations outside the European Union that process personal data in connection with offering goods or services to individuals in the EU or monitoring their behaviour.Â
One important distinction is that not every security incident is automatically a reportable personal data breach.Â
The organisation needs to understand what happened and assess the circumstances before determining whether notification is required.Â
Does GDPR require every security incident to be reported within 72 hours?
No.Â
Under Article 33 of GDPR, where a personal data breach is likely to result in a risk to the rights and freedoms of individuals, the controller must notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach.Â
The investigation may therefore need to establish:Â
- What personal data was involved? Â
- How many individuals could be affected? Â
- Was the data accessed, changed or disclosed? Â
- When did the organisation become aware of the breach? Â
- What steps were taken to contain the incident? Â
The security team may not be responsible for making the final legal or regulatory decision. Its role is to provide reliable technical information that allows privacy, legal and compliance teams to assess the situation.Â
Good logging and evidence preservation are therefore important not only for technical investigation but also for making informed compliance decisions.Â
Official reference: GDPR Article 33 — EUR-LexÂ
What Does ISO/IEC 27035 Cover for Incident Management?
When discussing incident management specifically, ISO/IEC 27035 is more directly relevant than ISO 27001.Â
ISO/IEC 27035 provides guidance for managing information security incidents, covering areas such as preparation, detection, reporting, assessment, response and lessons learned.Â
The standard takes a lifecycle approach to incident management.Â
An organisation needs to be prepared before an incident occurs. When a potential incident is detected, it needs to be reported and assessed. Once an incident is confirmed, appropriate response activities can be initiated, followed by recovery and post-incident activities.Â
Consider a phishing attack that results in a compromised employee account.Â
The immediate priority may be to secure the account, investigate the activity and determine whether the attacker reached other systems.Â
Once the immediate threat has been contained, the organisation also needs to understand what allowed the incident to occur.Â
- Was the account appropriately protected?Â
- Were the user's privileges suitable?Â
- Could the activity have been detected earlier?Â
- Are other accounts exposed to the same weakness?Â
- What controls need to be improved?Â
This is where lessons learned become important. Incident management should not end when the affected system is restored. Findings from an incident can help improve processes and security controls.Â
ISO/IEC 27001, meanwhile, provides the broader framework for establishing and continually improving an Information Security Management System (ISMS). ISO/IEC 27035 can complement that broader information-security management approach by providing more specific guidance on incident management.Â
Official reference: ISO/IEC 27035 — ISOÂ
Where Does SOC 2 Fit Into Incident Response?
SOC 2 is not an incident response standard.Â
It focuses on controls related to areas such as security, availability, processing integrity, confidentiality and privacy. These control areas are defined in the AICPA's Trust Services Criteria, which SOC 2 assessments are based on.Â
Incident-related controls may form part of a SOC 2 assessment depending on the scope of the engagement.Â
For an organisation, this can mean demonstrating that relevant processes and controls are not simply documented but are operating as intended.Â
The question is therefore not only whether an incident response policy exists. Organisations may also need to demonstrate that relevant controls and processes were followed and that appropriate evidence was maintained.Â
For organisations that need hands-on support, Eventus' Incident Response Service supports incident response planning, investigation, containment, remediation, recovery, and reporting.Â
Where Do Incident Response Plans Commonly Fall Short?
Most organisations already have some form of incident response capability.Â
They may have a response plan, security tools, escalation procedures and people responsible for different parts of the process.Â
The difficulties often become apparent when all of these elements have to work together during an actual incident.Â
A response plan may have been written some time ago. Since then, people may have changed roles, systems may have been replaced and new applications may have been introduced.Â
The document may still exist, but it may no longer reflect the current environment.Â
Security data can create a similar challenge. An organisation may have large volumes of logs but still struggle to find the specific information required during an investigation.Â
SIEM (Security Information and Event Management) and EDR (Endpoint Detection and Response) are two common categories of security tooling used to collect, correlate, and investigate activity across an environment.Â
Technologies such as SIEM and EDR can improve visibility, but technology alone does not determine how an incident is handled.Â
For organisations that require continuous visibility, 24×7 SOC monitoring can help security teams detect suspicious activity, investigate alerts and escalate potential incidents.Â
Communication can also become a problem. The SOC may know that an account has been compromised while the privacy or compliance team is still determining whether personal data was involved.Â
Recovery is another point where organisations can lose valuable information. Systems may be restored and the immediate threat removed, but if the underlying cause is not investigated, the same weakness may remain.Â
For this reason, incident response plans need to be reviewed and tested periodically rather than treated as documents that are completed once and stored.Â
How Does Eventus Security Support Incident Response?
Eventus Security supports organisations across incident response, incident readiness, digital forensics and incident response (DFIR), and 24×7 security operations.Â
Its Incident Response Service covers areas such as incident response planning, response playbooks, security-gap assessment, threat hunting, compromise assessment, digital forensics, root-cause analysis and recovery guidance.Â
Preparation is also an important part of incident readiness. Organisations can use activities such as tabletop exercises, maturity assessments and ransomware simulations to evaluate how their response processes perform before facing a real incident.Â
For organisations that require continuous monitoring, SOC as a Service provides 24×7 security monitoring, detection and response capabilities.Â
Eventus is also CERT-In empanelled, supporting organisations with cybersecurity assessment and compliance-related requirements in India.Â
The focus is on helping organisations prepare for incidents, investigate them effectively and use the findings to strengthen their security posture.Â
What Should Organisations Include in an Incident Response Compliance Plan?
A practical incident response compliance plan should connect security operations with the requirements that apply to the organisation.Â
At a minimum, organisations should consider:Â
- Clear incident classification and severity levels Â
- Defined roles and escalation responsibilities Â
- Up-to-date incident response procedures Â
- Reliable logging and evidence preservation Â
- Regulatory and contractual reporting requirements Â
- Communication procedures for internal and external stakeholders Â
- Regular testing of response plans Â
- Documentation of significant incidents Â
- Root-cause analysis and remediation Â
- Post-incident reviews and improvement Â
These elements help ensure that incident response is not limited to detecting and containing a threat. They also help organisations demonstrate how an incident was managed and what was done to reduce the likelihood of recurrence.Â
Frequently Asked Questions
What is incident response compliance?
Incident response compliance means managing and documenting security incidents in accordance with the regulatory, security and contractual requirements applicable to an organisation.Â
Does every organisation have to follow CERT-In requirements?
CERT-In requirements apply to organisations and entities within the scope of the applicable Indian cybersecurity directions. Organisations should assess their specific obligations rather than assuming that every requirement applies to every business.Â
Does GDPR require every security incident to be reported within 72 hours?
No. The 72-hour requirement applies to qualifying personal data breaches where the conditions under Article 33 are met.Â
Is ISO 27001 the same as ISO/IEC 27035?
No. ISO/IEC 27001 provides a broader framework for an Information Security Management System (ISMS), while ISO/IEC 27035 focuses specifically on information security incident management.Â
Does SOC 2 cover incident response?
SOC 2 is not an incident response standard. However, relevant incident-management controls may be assessed depending on the scope of the SOC 2 engagement.Â
How Can Organisations Build a More Prepared Incident Response Capability?
Incident response requirements differ from one organisation to another. What remains consistent is the need to understand what happened, contain the threat, preserve relevant evidence and make informed decisions about the next steps.Â
Regular testing, reliable security visibility, clear responsibilities and effective evidence management can help organisations respond more effectively when an incident occurs.Â
For organisations looking to strengthen their incident response capability, Eventus Security provides incident response, incident readiness, DFIR and 24×7 security operations.Â







