BRACKETOLOGY | FEDRAMP
IR-2: INCIDENT RESPONSE TRAINING
-
FedRAMP Baseline Membership IR-2:
- LOW
- MODERATE
- HIGH
FedRAMP Bracketology
Use the FedRAMP Control Membership information above to determine if a control or control enhancement is required for each Impact Baseline — LOW, MODERATE, or HIGH
Click on the panel below each control or control enhancement to review the FedRAMP Impact Baseline-specific control configuration requirements for each of the [BRACKETS] in each control and/or control enhancement.
Review and use Additional Requirements and Guidance to build FedRAMP-compliant controls for your risk-based cybersecurity program.
To change the baseline view in the panel, click on LOW, MODERATE, or HIGH when the panel is open
Panels only appear where there are [BRACKETS] in the control or enhancement or where there is FedRAMP-specific requirements or guidance available.
The organization provides incident response training to information system users consistent with assigned roles and responsibilities:
- a. Within [Assignment: organization-defined time period] of assuming an incident response role or responsibility;
- b. When required by information system changes; and
- c. [Assignment: organization-defined frequency] thereafter.
Click Low | Moderate | High below to see FedRAMP control configuration information. It's in BOLD.
The organization provides incident response training to information system users consistent with assigned roles and responsibilities:
- a. Within organization-defined time period of assuming an incident response role or responsibility;
- b. When required by information system changes; and
- c. at least annually thereafter.
The organization provides incident response training to information system users consistent with assigned roles and responsibilities:
- a. Within organization-defined time period of assuming an incident response role or responsibility;
- b. When required by information system changes; and
- c. at least annually thereafter.
The organization provides incident response training to information system users consistent with assigned roles and responsibilities:
- a. Within ten (10) days of assuming an incident response role or responsibility;
- b. When required by information system changes; and
- c. at least annually thereafter.
SUPPLEMENTAL GUIDANCE
Incident response training provided by organizations is linked to the assigned roles and responsibilities of organizational personnel to ensure the appropriate content and level of detail is included in such training. For example, regular users may only need to know who to call or how to recognize an incident on the information system; system administrators may require additional training on how to handle/remediate incidents; and incident responders may receive more specific training on forensics, reporting, system recovery, and restoration. Incident response training includes user training in the identification and reporting of suspicious activities, both from external and internal sources.
RELATED CONTROLS: IR-2
CONTROL ENHANCEMENTS
IR-2 (1) INCIDENT RESPONSE TRAINING | SIMULATED EVENTS
-
FedRAMP Baseline Membership IR-2 (1):
- HIGH
The organization incorporates simulated events into incident response training to facilitate effective response by personnel in crisis situations.
Supplemental Guidance: NONE
IR-2 (2) INCIDENT RESPONSE TRAINING | AUTOMATED TRAINING ENVIRONMENTS
-
FedRAMP Baseline Membership IR-2 (2):
- HIGH
The organization employs automated mechanisms to provide a more thorough and realistic incident response training environment.
Supplemental Guidance: NONE
REFERENCES:
- NIST Special Publication 800-16
- NIST Special Publication 800-50