Control statement
a. Provide incident response training to system users consistent with assigned roles and responsibilities:
1. Within {{ insert: param, ir-02_odp.01 }} of assuming an incident response role or responsibility or acquiring system access;
2. When required by system changes; and
3. {{ insert: param, ir-02_odp.02 }} thereafter; and
b. Review and update incident response training content {{ insert: param, ir-02_odp.03 }} and following {{ insert: param, ir-02_odp.04 }}. Parameter placeholders {{ insert: param, … }} reference FedRAMP-set values in the resolved profile. Full parameter map is
preserved in the catalog database.
Covered by these Key Security Indicators
| KSI | Title | Category |
|---|---|---|
| KSI-CED-03 | Development and Engineering Training _Persistently_ review the effectiveness of role-specific training given to development and engineering staff that covers best practices for delivering secure software. | Cybersecurity Education |