Incident response policies for regulated manufacturers fail when the agent drafts a generic template rather than integrating the organisation-specific gap analysis findings, governance mandate, operational runbook, and regulatory guidance into a facility- and product-context-specific policy.
Scanned 9/11/2026
Install to Claude Code
npx -y skills add sunyifeisb-art/legalwork --skill draft-cybersecurity-incident-response-policy --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Draft Cybersecurity Incident Response Policy?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/sunyifeisb-art-draft-cybersecurity-incident-response-policy)More formats (shields.io, HTML) on the badges page.
---
name: draft-cybersecurity-incident-response-policy
task_id: data-privacy-cybersecurity/draft-cybersecurity-incident-response-policy
description: Incident response policies for regulated manufacturers fail when the agent drafts a generic template rather than integrating the organisation-specific gap analysis findings, governance mandate, operational runbook, and regulatory guidance into a facility- and product-context-specific policy.
activates_for: [planner, solver, checker]
---
# Skill: Draft Cybersecurity Incident Response Policy for Public Medical Device Manufacturer
## 1. Subject-matter triage
- Treat the source set as a policy-drafting record, not a template exercise.
- Identify the governing mandate first; it controls scope, authority, escalation, and reporting.
- Pull out the operational state from the runbook and after-action materials before drafting any rule.
- Separate mandatory policy content from implementation notes so the policy reads as a governing instrument, not a memo.
- If the source set contains more than one facility, product line, or business unit, map the policy to each in scope before drafting the final text.
- If the source set contains only one operating context, state that the policy is limited to that context and draft accordingly.
## 2. Failure modes the skill is correcting
- Drafting a generic cybersecurity incident response template that ignores the organisation’s actual gaps, workflows, and governance structure.
- Treating the governing resolution or equivalent authority as background instead of the source of policy authority.
- Missing mandatory elements drawn from regulatory guidance for a regulated medical device manufacturer.
- Failing to align the policy with public-company disclosure obligations where incident materiality may trigger external reporting.
- Omitting coordination points with insurance, privacy, legal, IT, quality, regulatory, and executive functions.
- Producing a companion drafting notes memo that merely summarizes the policy instead of explaining why each provision was selected.
- Leaving open who decides, who escalates, who reports, and when each step occurs.
- Allowing incident handling to remain aspirational rather than operational, measurable, and assignable.
## 3. Legal frameworks / domain conventions that apply
- Medical device cybersecurity lifecycle obligations: the policy should reflect post-market security expectations, incident handling, remediation, and documentation duties applicable to regulated manufacturers.
- Public-company disclosure obligations: include a materiality assessment and escalation path for potential securities-law disclosure decisions under the applicable disclosure regime.
- Privacy and security safeguard requirements: if personal or health information may be involved, include administrative incident-response controls and breach-assessment workflow consistent with the applicable privacy/security rules.
- Recognized cybersecurity incident-response structure: organize the policy around prepare, detect, analyze, contain, eradicate, recover, and review functions, with the operative content centered on response and recovery.
- Insurance coordination rules: if the source materials reference cyber-insurance, capture notice triggers, timing, approval prerequisites, and any restrictions on response spend or vendor use.
- Governance and delegation conventions: policy authority must track the governing body or delegated officer named in the source materials and should not expand beyond that mandate.
## 4. Analytical scaffolds
- Read the governing mandate to extract the policy’s authority, scope, required approvers, escalation hierarchy, and any required board or executive reporting.
- Read the gap analysis to identify each missing or weak control that the policy must cure.
- Read the operational runbook and after-action material to see how incidents are actually handled and where the policy must convert practice into mandatory steps.
- Read the regulatory guidance for any required policy elements, timing expectations, documentation duties, or reporting triggers.
- Read any insurance excerpt for notice requirements, consent restrictions, and coordination obligations.
- Draft the policy as a formal governance document with clear sections for purpose, scope, definitions, roles, classification, detection, escalation, containment, communications, recovery, review, and maintenance.
- Translate every material gap into a specific rule, owner, or timing requirement rather than a general statement of intent.
- Draft the companion notes memo as a drafting rationale document that ties each major provision to a source document and explains the implementation choice.
- Where the sources imply multiple incident categories, roles, facilities, or reporting paths, enumerate them explicitly before drafting the operative rules.
- Use mandatory language for obligations and avoid aspirational phrasing unless the source documents clearly support discretion.
## 5. Vertical / structural / temporal relationships
- Governance mandate sets the ceiling and floor for the policy; the policy implements that authority without altering it.
- The gap analysis identifies what is missing; the policy should close each gap with a concrete requirement.
- Operational practice shows what happens in reality; the policy should formalize, correct, or constrain that practice.
- Regulatory or disclosure windows may run faster than internal approval chains; build escalation and decision points early enough to preserve compliance.
- External notifications, insurer notices, and internal leadership escalation should be sequenced so that one does not block another.
- Recovery and post-incident review should follow containment and remediation, with lessons learned feeding back into policy maintenance.
## 6. Output structure conventions
- Produce two deliverables: the cybersecurity incident response policy and the policy drafting notes memo.
- Draft the policy as the primary deliverable first; only then draft the notes memo.
- Make the policy a standalone instrument with operative provisions, named roles, effective-date logic, and review cycle.
- Make the notes memo concise but specific, with each major drafting choice tied to the source material that drove it.
- Use industry-conventional headings rather than a rubric-shaped list.
- Keep the policy internally usable by operations, legal, quality, and executive stakeholders.
- Ensure the final files are named exactly as instructed by the workflow and contain substantive content, not placeholders.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!