This objective verifies that your organization has formally documented its incident response process and procedures, as identified in IR.L2-3.6.1[a]. It’s not enough to have a verbal or ad hoc plan—assessors must see evidence that a defined, actionable, and complete process exists in writing.