💼 IR-1 Policy and Procedures (L)(M)(H)
- ID: /frameworks/fedramp-moderate-security-controls/ir/01
Description​
a. Develop, document, and disseminate to [Assignment: organization-defined personnel or roles]:
- 
[Selection (one-or-more): organization-level; mission/business process-level; system-level] incident response policy that: (a) Addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and (b) Is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines; and 
- 
Procedures to facilitate the implementation of the incident response policy and the associated incident response controls; 
b. Designate an [Assignment: organization-defined official] to manage the development, documentation, and dissemination of the incident response policy and procedures; and
c. Review and update the current incident response:
- 
Policy [FedRAMP Assignment: at least every three (3) years] and following [Assignment: organization-defined events]; and 
- 
Procedures [FedRAMP Assignment: at least annually] and following [FedRAMP Assignment: significant changes]. 
Similar​
- Sections
- /frameworks/fedramp-high-security-controls/ir/01
 
- Internal
- ID: dec-c-275b8758
 
- ID: 
Similar Sections (Take Policies From)​
| Section | Sub Sections | Internal Rules | Policies | Flags | Compliance | 
|---|---|---|---|---|---|
| 💼 FedRAMP High Security Controls → 💼 IR-1 Policy and Procedures (L)(M)(H) | no data | 
Sub Sections​
| Section | Sub Sections | Internal Rules | Policies | Flags | Compliance | 
|---|