FedRAMP Controls / IR

IR-3 Incident Response Testing

Family IR
Baselines moderate
Mapped KSIs 3

Control statement

Test the effectiveness of the incident response capability for the system {{ insert: param, ir-03_odp.01 }} using the following tests: {{ insert: param, ir-03_odp.02 }}.
        Requirement: The service provider defines tests and/or exercises in accordance with NIST Special Publication 800-61 (as amended). Functional testing must occur prior to testing for initial authorization. Annual functional testing may be concurrent with required penetration tests (see CA-8). The service provider provides test plans to the JAB/AO annually. Test plans are approved and accepted by the JAB/AO prior to test commencing.

Parameter placeholders {{ insert: param, … }} reference FedRAMP-set values in the resolved profile. Full parameter map is preserved in the catalog database.

Covered by these Key Security Indicators

KSITitleCategory
KSI-INR-02Incident Review
_Persistently_ review past incidents for patterns or _vulnerabilities_.
Incident Response
KSI-INR-03Incident After Action Reports
Generate incident after action reports and _persistently_ incorporate lessons learned.
Incident Response
KSI-RPL-04Recovery Testing
_Persistently_ test the capability to recover from incidents and contingencies, including alignment with defined recovery objectives.
Recovery Planning