National Vulnerability Database

National Vulnerability Database

National Vulnerability
Database

NIST Special Publication 800-53 (Rev. 4)

Security Controls and Assessment Procedures for Federal Information Systems and Organizations

IR-2 INCIDENT RESPONSE TRAINING

Family:
IR - INCIDENT RESPONSE
Class:
Priority:
P2 - Implement P2 security controls after implementation of P1 controls.
Baseline Allocation:
Low Moderate High
IR-2 IR-2 IR-2 (1) (2)

Control Description

The organization provides incident response training to information system users consistent with assigned roles and responsibilities:

a. Within [Assignment: organization-defined time period] of assuming an incident response role or responsibility;

b. When required by information system changes; and

c. [Assignment: organization-defined frequency] thereafter.

Supplemental Guidance

Incident response training provided by organizations is linked to the assigned roles and responsibilities of organizational personnel to ensure the appropriate content and level of detail is included in such training. For example, regular users may only need to know who to call or how to recognize an incident on the information system; system administrators may require additional training on how to handle/remediate incidents; and incident responders may receive more specific training on forensics, reporting, system recovery, and restoration. Incident response training includes user training in the identification and reporting of suspicious activities, both from external and internal sources.

Related to: AT-3CP-3IR-8

Control Enhancements

IR-2(1) INCIDENT RESPONSE TRAINING | SIMULATED EVENTS
The organization incorporates simulated events into incident response training to facilitate effective response by personnel in crisis situations.
IR-2(2) INCIDENT RESPONSE TRAINING | AUTOMATED TRAINING ENVIRONMENTS
The organization employs automated mechanisms to provide a more thorough and realistic incident response training environment.