Skip to main content

πŸ’Ό IR-8 Incident Response Plan (L)(M)(H)

  • Contextual name: πŸ’Ό IR-8 Incident Response Plan (L)(M)(H)
  • ID: /frameworks/fedramp-moderate-security-controls/ir/08
  • Located in: πŸ’Ό Incident Response

Description​

a. Develop an incident response plan that:

  1. Provides the organization with a roadmap for implementing its incident response capability;

  2. Describes the structure and organization of the incident response capability;

  3. Provides a high-level approach for how the incident response capability fits into the overall organization;

  4. Meets the unique requirements of the organization, which relate to mission, size, structure, and functions;

  5. Defines reportable incidents;

  6. Provides metrics for measuring the incident response capability within the organization;

  7. Defines the resources and management support needed to effectively maintain and mature an incident response capability;

  8. Addresses the sharing of incident information;

  9. Is reviewed and approved by [Assignment: organization-defined personnel or roles] [FedRAMP Assignment: at least annually]; and

  10. Explicitly designates responsibility for incident response to [Assignment: organization-defined entities, personnel, or roles].

b. Distribute copies of the incident response plan to [FedRAMP Assignment: see additional FedRAMP Requirements and Guidance];

c. Update the incident response plan to address system and organizational changes or problems encountered during plan implementation, execution, or testing;

d. Communicate incident response plan changes to [FedRAMP Assignment: see additional FedRAMP Requirements and Guidance]; and

e. Protect the incident response plan from unauthorized disclosure and modification.

IR-8 Additional FedRAMP Requirements and Guidance:

(b) Requirement: The service provider defines a list of incident response personnel (identified by name and/or by role) and organizational elements. The incident response list includes designated FedRAMP personnel.

(d) Requirement: The service provider defines a list of incident response personnel (identified by name and/or by role) and organizational elements. The incident response list includes designated FedRAMP personnel.

Similar​

  • Sections
    • /frameworks/fedramp-high-security-controls/ir/08
  • Internal
    • ID: dec-c-a7da9af2

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό FedRAMP High Security Controls β†’ πŸ’Ό IR-8 Incident Response Plan (L)(M)(H)

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags