CCI-000815
CCI-000815 Definition
| Status | |
| Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
Determine if: - incident response training content is reviewed and updated [IR-02_ODP[03]; frequency at which to review and update incident response training content is defined]. - incident response training content is reviewed and updated following [IR-02_ODP[04]; events that initiate a review of the incident response training content are defined].
Validation Procedures
Examine: [SELECT FROM: Incident response policy; procedures addressing incident response training; incident response training curriculum; incident response training materials; privacy plan; incident response plan; incident response training records; system security plan; privacy plan; other relevant documents or records]. Interview: [SELECT FROM: Organizational personnel with incident response training and operational responsibilities; organizational personnel with information security and privacy responsibilities].