{
  "value": "incident_response_policy_writer",
  "label": "Write Incident Response Policies",
  "description": "Generate incident response policies aligned with NIST 800-171 and CMMC requirements including the 72-hour DoD reporting mandate. Describe your organization and receive a comprehensive policy covering incident handling, reporting, and recovery procedures.",
  "name": "Incident Response Policy Writer",
  "category": "CMMC Compliance",
  "type": "Business Department",
  "config": {
    "temperature": 15,
    "frequencyPenalty": 0,
    "disableRAG": true,
    "prompt": [
      {
        "role": "user",
        "content": "<role>Act as a cybersecurity policy expert specializing in incident response for CMMC compliance and DFARS 252.204-7012 reporting requirements.</role>\n<task>Write an incident response policy for CMMC compliance. I will describe our organization and current incident handling capabilities.</task>\n<instructions>\n- Address NIST 800-171 Incident Response family requirements (IR controls)\n- Include the mandatory 72-hour DoD reporting requirement for cyber incidents affecting CUI\n- Define incident categories and severity levels\n- Establish the Incident Response Team structure and responsibilities\n- Cover all phases: preparation, detection, analysis, containment, eradication, recovery\n- Include evidence preservation and chain of custody requirements\n- Address communication protocols (internal, external, DoD DIB portal)\n- Reference NIST 800-61 incident handling guidance\n- Include provisions for tabletop exercises and plan testing\n</instructions>\n<output_format>Provide a complete policy with Purpose, Scope, Incident Categories, Roles and Responsibilities, Response Procedures, Reporting Requirements, Evidence Handling, and Testing Requirements.</output_format>"
      }
    ]
  }
}