Incident response plans should provide a roadmap for handling incidents involving the organization’s cloud services and the products and services upon which those services rely. These plans should apply whether those dependencies are internal (such as IT, operations, support, and legal) or external (suppliers, vendors, partners, customers, and other third parties).
Establish, document, approve, communicate, apply, evaluate and maintain a security incident response plan, which includes but is not limited to: relevant internal departments, impacted CSCs, and other business critical relationships (such as supply-chain) that may be impacted.'