FedRAMP Moderate
IR - Incident Response

FedRAMP Moderate IR-2: Incident Response Training

Requires incident response training for system users consistent with their assigned roles, within a defined period of assuming the role and periodically thereafter.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 90 controls across 42 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27001:2022 · 5 controls

  • 5.24 Information security incident management planning and preparation 
  • 5.26 Response to information security incidents
  • 5.27 Learning from information security incidents
  • 5.28 Collection of evidence
  • 6.3 Information security awareness, education and training

CIS Controls v8 · 4 controls

  • CIS-11.1 Establish and Maintain a Data Recovery Process
  • CIS-13.1 Centralize Security Event Alerting
  • CIS-17.4 Establish and Maintain an Incident Response Process
  • CIS-17.7 Conduct Routine Incident Response Exercises

ISO 27002:2022 · 4 controls

  • 5.24 Information security incident management planning and preparation
  • 5.26 Response to information security incidents
  • 5.27 Learning from information security incidents
  • 5.28 Collection of evidence
  • NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process
  • NIST-CSF-RS.MA-01 The incident response plan is executed in coordination with relevant third parties once an incident is declared
  • NIST-CSF-RS.MI-01 Incidents are contained
  • NIST-CSF-RS.MI-02 Incidents are eradicated

NIST SP 800-53 Rev 5 · 4 controls

PCI DSS 4.0 · 4 controls

  • 12.10.1 12.10.1 Incident response plan ready for activation
  • 12.10.2 12.10.2 Annual review and testing of the incident response plan
  • 12.10.3 12.10.3 Incident response personnel available 24/7
  • 12.10.5 12.10.5 Plan covers alerts from security monitoring systems

SOC 2 · 4 controls

  • SOC2-A1.3 A1.3 Testing recovery plan procedures
  • SOC2-CC7.3 CC7.3 Evaluating security events to identify incidents
  • SOC2-CC7.4 CC7.4 Responding to security incidents
  • SOC2-P6.6 P6.6 Notifying breaches and incidents

BSI IT-Grundschutz · 3 controls

  • BSI-13 Risk assessment procedures
  • BSI-15 Security categorization
  • BSI-17 Continuous monitoring strategy

ISO/IEC 29134:2023 · 3 controls

  • 29134-1 Scope
  • 29134-3 Terms and definitions
  • 29134-9.1 PIA report structure

API 1164 · 2 controls

  • API1164-07 Remote Access
  • API1164-24 Vulnerability assessment for critical systems

IEC 62443 · 2 controls

  • IEC62443-07 Personnel risk assessment
  • IEC62443-24 Vulnerability assessment for critical systems

ISO 22301:2019 · 2 controls

  • 27557-4.3 Individual impact consideration
  • 27557-6.3 Privacy risk assessment

NIST SP 800-181 · 2 controls

  • 2.4.4 Hazard Analysis and Risk Assessment
  • 2.7.2 Food Fraud Plan
  • CH-FADP-21 Data protection impact assessments
  • FADP-7 Data Protection Impact Assessment (Articles 9-10)
  • CRM-1 AML/CFT Compliance
  • CRM-4 Business Risk Assessment
  • AMLCTF-PartA-RiskAssess ML/TF Risk Assessment
  • CPS230-11 Identification, Assessment and Management of Operational Risk
  • 4.3.1 Risk Assessment and Impact Analysis

Bahrain PDPL · 1 control

  • BB-DPA-20 Sections 50-60 - Registration and Responsibilities

C5 (Germany) · 1 control

  • C5-HR-03 Security training and awareness programme

DORA · 1 control

  • CJIS-17 Risk Assessment

GDPR · 1 control

HIPAA Security Rule · 1 control

ISO/IEC 27031:2011 · 1 control

  • 27031-7.2 Resource Requirements

ISO/IEC 29147:2018 · 1 control

  • 29147-5.11 Researcher Safe Harbour and Legal Posture

NIST SP 800-172 · 1 control

  • 3.2.2e Practical Exercises in Awareness Training
  • IR-2 IR-2 Incident Response Training
  • IR-2 IR-2 Incident Response Training
  • IR-2 IR-2 Incident Response Training
  • IM8-SEC.4 Vulnerability Management
  • CPSC-RA.3 Lifecycle Risk Assessment

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in IR - Incident Response

You are reading one control. How much of FedRAMP Moderate have you already done?

FedRAMP Moderate IR-2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of FedRAMP Moderate your existing evidence covers. Hold ISO 27002:2022 and 182 of 323 FedRAMP Moderate controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 348 were rejected on the ISO 27002:2022 pair alone.

Query this from an agent

The graph holds this control, the 90 it maps to, and the evidence behind each claim, over MCP and REST.