Scope
Define incident types covered (cybersecurity, physical safety, supply chain) and excluded events; include triggers for escalation and thresholds for external notifications.
A clear Business CIRP Document reduces recovery time, clarifies decision authority, and documents regulatory obligations. It supports incident containment, evidence preservation, and consistent stakeholder communication while helping demonstrate reasonable safeguards to regulators, insurers, and customers.
Several internal groups collaborate to create and approve a CIRP Document; the precise mix depends on company size and industry.
Maintain a single source of truth and keep an approval log so responsibility and version history are auditable.
Define incident types covered (cybersecurity, physical safety, supply chain) and excluded events; include triggers for escalation and thresholds for external notifications.
List named primary and backup responders, legal counsel, public relations contacts, insurers, and third-party vendors with phone, email, and escalation order for rapid contact.
Provide step-by-step actions for initial containment, evidence preservation, system isolation, and preliminary impact assessment to avoid destroying forensic value.
Include internal and external templates, approval workflow for public statements, and guidance on regulator and customer notifications, plus required retention of communications.
Summarize industry-specific reporting deadlines, data breach notification laws, and document the decision process for engaging counsel or regulators.
Describe root-cause analysis steps, remediation tracking, lessons‑learned sessions, and version control for plan updates and staff training.
| Field | Configuration |
|---|---|
| Approval Order | Sequential: Security → Legal → CEO |
| Authentication | Email + optional SMS code for external signers |
| Required Fields | Effective Date, Primary Contact, Escalation Threshold |
| Retention | Retain signed copy and audit trail for required period |
Ensure the chosen platform meets your compliance needs and preserves a tamper-evident audit trail for each signed version.
Complete a full review every 12 months.
Run at least one exercise every 6–12 months.
Reapprove after material changes or annually.
Update within 30 days of major incidents.
Communicate updates within 14 days of approval.
All sections populated and internal comments resolved.
Security, IT, Legal and Operations review content.
Designated officer signs and dates the plan.
Distribute plan and schedule staff briefings.
| Criteria | signNow | DocuSign | Adobe Sign |
|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo |
| Bulk Send | |||
| Audit Trail | |||
| HIPAA BAA |
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial | Yes | Yes | Yes | Yes |
| Bulk Send | Yes | Yes | Yes | Yes | No |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| Envelope Cap | No cap | 100 envelopes/user/year | Varies | Varies | Varies |
Founder Tim Martin streamlined incident response signoffs using online approvals and secure storage.
Founder John Butler needed compliant digital workflows for clinical and operational approvals.