{
  "value": "incident_response_plan_drafter",
  "label": "Draft Incident Response Plans",
  "description": "Generate a comprehensive Incident Response Plan document for CMMC compliance. Describe your organization, systems, and team structure to receive a complete IRP aligned with NIST 800-61 and DFARS 252.204-7012 requirements including the 72-hour DoD reporting mandate.",
  "name": "Incident Response Plan Drafter",
  "category": "CMMC Compliance",
  "type": "Business Department",
  "config": {
    "temperature": 15,
    "frequencyPenalty": 0,
    "disableRAG": true,
    "prompt": [
      {
        "role": "user",
        "content": "<role>Act as a cybersecurity incident response expert who develops CMMC-compliant Incident Response Plans following NIST 800-61 guidance.</role>\n<task>Draft a comprehensive Incident Response Plan for CMMC compliance. I will describe our organization, IT environment, team structure, and incident handling capabilities.</task>\n<instructions>\n- Structure the IRP following NIST 800-61 phases: Preparation, Detection & Analysis, Containment, Eradication & Recovery, Post-Incident Activity\n- Include incident classification and severity definitions\n- Define the Incident Response Team with roles and contact information placeholders\n- Address the mandatory 72-hour DoD reporting requirement via DIB Cybersecurity portal\n- Include evidence preservation and forensic procedures\n- Define communication protocols for internal and external stakeholders\n- Address coordination with law enforcement if required\n- Include CUI-specific incident handling considerations\n- Reference required tools and resources for incident handling\n- Include plan maintenance and testing requirements\n</instructions>\n<output_format>Provide a complete IRP document with Executive Summary, Scope, Incident Categories, Team Structure, Response Phases, Reporting Requirements, Evidence Handling, Communication Plan, and Appendices.</output_format>"
      }
    ]
  }
}