Fedramp system Security Plan (ssp) High Baseline Template


IR-3 Incident Response Testing (H)



Download 1.2 Mb.
Page258/478
Date16.12.2020
Size1.2 Mb.
#54609
1   ...   254   255   256   257   258   259   260   261   ...   478
FedRAMP-SSP-High-Baseline-Template
FedRAMP-SSP-High-Baseline-Template, North Carolina Summary Table of Ecoregion Characteristics

IR-3 Incident Response Testing (H)


The organization tests the incident response capability for the information system [FedRAMP Assignment: at least every six (6) months] using [FedRAMP Assignment: see additional FedRAMP Requirements and Guidance] to determine the incident response effectiveness and documents the results.

IR-3 Additional FedRAMP Requirements and Guidance:

Requirements: The service provider defines tests and/or exercises in accordance with NIST Special Publication 800-61 (as amended). For JAB authorization, the service provider provides test plans to the JAB/AO annually. Test plans are approved and accepted by the JAB/AO prior to the test commencing.

IR-3


Download 1.2 Mb.

Share with your friends:
1   ...   254   255   256   257   258   259   260   261   ...   478




The database is protected by copyright ©ininet.org 2024
send message

    Main page