IR-2—Incident Response Training
>Control Description
>Supplemental Guidance
Incident response training provided by organizations is linked to the assigned roles and responsibilities of organizational personnel to ensure the appropriate content and level of detail is included in such training. For example, regular users may only need to know who to call or how to recognize an incident on the information system; system administrators may require additional training on how to handle/remediate incidents; and incident responders may receive more specific training on forensics, reporting, system recovery, and restoration. Incident response training includes user training in the identification and reporting of suspicious activities, both from external and internal sources.
Related controls: AT-3, CP-3, IR-8
>Profile-Specific Parameters
(B) frequency [at a frequency no longer than annually]
Ask AI
Configure your API key to use AI features.