Skip to main content

πŸ’Ό IR-1 Policy and Procedures (L)(M)(H)

  • Contextual name: πŸ’Ό IR-1 Policy and Procedures (L)(M)(H)
  • ID: /frameworks/fedramp-moderate-security-controls/ir/01
  • Located in: πŸ’Ό Incident Response

Description​

a. Develop, document, and disseminate to [Assignment: organization-defined personnel or roles]:

  1. [Selection (one-or-more): organization-level; mission/business process-level; system-level] incident response policy that:

    (a) Addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and

    (b) Is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines; and

  2. Procedures to facilitate the implementation of the incident response policy and the associated incident response controls;

b. Designate an [Assignment: organization-defined official] to manage the development, documentation, and dissemination of the incident response policy and procedures; and

c. Review and update the current incident response:

  1. Policy [FedRAMP Assignment: at least every three (3) years] and following [Assignment: organization-defined events]; and

  2. Procedures [FedRAMP Assignment: at least annually] and following [FedRAMP Assignment: significant changes].

Similar​

  • Sections
    • /frameworks/fedramp-high-security-controls/ir/01
  • Internal
    • ID: dec-c-275b8758

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό FedRAMP High Security Controls β†’ πŸ’Ό IR-1 Policy and Procedures (L)(M)(H)

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags