Policy templates/Resilience & Incident Response/Version 1.0

Crisis Management Policy Template

Summary

Defines how the organization prepares for, escalates, coordinates, communicates, and resolves crisis events that harm operations, reputation, or stakeholders. Covers crisis triggers, team roles, decision-making, communications, response-plan interfaces, exercises, and documentation.

Purpose

This policy outlines the organization's approach to managing and responding to crisis events that have the potential to cause significant harm to operations, reputation, or stakeholders. It ensures that all personnel understand their roles and that effective coordination, communication, and recovery actions are undertaken during a crisis.

Scope

This policy applies to all business units, employees, contractors, and third parties involved in the organization's crisis response. It encompasses crisis identification, activation of the Crisis Management Team (CMT), communication, escalation, decision-making, and resolution across all business functions and geographies.

Framework Mapping

Appendix A includes mappings to common security and compliance frameworks for this template.
ISO/IEC 27002:2022
5.29 Information Security During Disruption5.31 Lessons Learned from Information Security Incidents
SOC 2 TSC
CC7.1: Incident response planCC7.4: Lessons learned
NIST CSF v2.0
RS.CO-1: Incident response coordinationRC.CO-2: Lessons learned incorporated
NIST SP 800-53 Rev. 5
IR-4: Incident HandlingIR-8: Incident Response Plan

Complete table of contents

This preview shows the full structure of the template. Create an account or sign in to download the complete editable policy.
  1. 1. Purpose
  2. 2. Scope
  3. 3. Policy Statement
  4. 3.1 Planning and Preparedness
  5. 3.2 Interfaces with Other Plans
  6. 3.3 Responsibilities of the Crisis Management Team
  7. 3.4 Crisis Definition and Triggers
  8. 3.5 Crisis Management Process
  9. 3.5.1 Detection and Escalation
  10. 3.5.2 Activation and Notification
  11. 3.5.3 Assessment and Coordination
  12. 3.5.4 Recovery and Closure
  13. 3.5.5 Documentation and Audit Trail
  14. 3.6 Communications Guidelines
  15. 3.7 Simulations and Exercises
  16. 3.8 Post-Crisis Review
  17. 4. Roles and Responsibilities
  18. 5. References and Related Policies
  19. 6. Definitions
  20. 7. Policy Exceptions
  21. 8. Compliance and Monitoring
  22. 9. Policy Review
  23. Appendix A: Framework Control Mapping
  24. Appendix B: Revision History
  25. Appendix C: Approvals

Download the complete crisis management policy template

Use the full editable template as a starting point, then adapt it to your organization.