The communication plan is the appropriate document because it establishes who must be contacted during an incident, how communications should occur, which channels are authorized, and how information should be escalated to internal and external stakeholders.
Incident-response communications may involve security personnel, executive leadership, legal counsel, privacy teams, public relations, human resources, business owners, vendors, regulators, law enforcement, customers, and other parties depending on incident severity. NIST's incident-response guidance emphasizes coordination with relevant stakeholders as part of an effective response capability. A communication plan operationalizes that requirement by maintaining contact information, responsibilities, escalation paths, notification requirements, and approved communication methods.
An organization chart identifies reporting relationships but may not contain emergency contact details, alternate channels, external contacts, or escalation procedures. A previous incident report documents a historical event and should not be treated as the authoritative contact source. Standard operating procedures can describe technical or administrative steps, but stakeholder communications are more appropriately centralized in the incident communication plan.
Maintaining this information in advance is critical because incident response frequently occurs under time pressure and may involve unavailable or compromised normal communication systems.
Study Guide Reference: Reporting and Communication → Communication Plan → Stakeholder Contacts → Escalation Paths → Internal/External Notifications → Out-of-Band Communications.