Control statement
- a.Provide incident response training to system users consistent with assigned roles and responsibilities:
- 1.Within [Organization-defined: time period] of assuming an incident response role or responsibility or acquiring system access;
- 2.When required by system changes; and
- 3.[Organization-defined: frequency] thereafter; and
- b.Review and update incident response training content [Organization-defined: frequency] and following [Organization-defined: events].
Discussion
Incident response training is associated with the assigned roles and responsibilities of organizational personnel to ensure that the appropriate content and level of detail are included in such training. For example, users may only need to know who to call or how to recognize an incident; system administrators may require additional training on how to handle incidents; and incident responders may receive more specific training on forensics, data collection techniques, reporting, system recovery, and system restoration. Incident response training includes user training in identifying and reporting suspicious activities from external and internal sources. Incident response training for users may be provided as part of [AT-2](#at-2) or [AT-3](#at-3) . Events that may precipitate an update to incident response training content include, but are not limited to, incident response plan testing or response to an actual incident (lessons learned), assessment or audit findings, or changes in applicable laws, executive orders, directives, regulations, policies, standards, and guidelines.
Organization-defined parameters
These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.
From control text to operational evidence
Use Incident Response Training as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to prepared detection, coordinated response, analysis, reporting, and lessons learned.
Implementation workflow
- Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
- Resolve each organization-defined parameter before declaring the control implemented.
- Document how the implementation satisfies every clause of the official control statement.
- Collect evidence as a normal byproduct of operation rather than only before an assessment.
- Review exceptions, changes, and monitoring results on a risk-based cadence.
Evidence examples
- incident response plans and playbooks
- case records and timelines
- exercise and tabletop results
- lessons-learned and corrective-action tracking
Common failure patterns
- plans that do not match current architecture
- unclear authority for containment decisions
- evidence lost during response
- lessons learned recorded but not implemented
Questions practitioners should ask
- What risk decision is this control intended to support in this system?
- Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
- Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
- What event or threshold requires the implementation to be reviewed or changed?
Assessment objectives and methods
Show the assessment objective
- IR-02a.
- IR-02a.01incident response training is provided to system users consistent with assigned roles and responsibilities within [Organization-defined: time period] of assuming an incident response role or responsibility or acquiring system access;
- IR-02a.02incident response training is provided to system users consistent with assigned roles and responsibilities when required by system changes;
- IR-02a.03incident response training is provided to system users consistent with assigned roles and responsibilities [Organization-defined: frequency] thereafter;
- IR-02b.
- IR-02b.[01]incident response training content is reviewed and updated [Organization-defined: frequency];
- IR-02b.[02]incident response training content is reviewed and updated following [Organization-defined: events].
Examine
- Incident response policy
- procedures addressing incident response training
- incident response training curriculum
- incident response training materials
- privacy plan
- incident response plan
- incident response training records
- system security plan
- privacy plan
- other relevant documents or records
Interview
- Organizational personnel with incident response training and operational responsibilities
- organizational personnel with information security and privacy responsibilities
Related controls
These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.
Control enhancements
Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.
IR-2(1) — Simulated Events
Incorporate simulated events into incident response training to facilitate the required response by personnel in crisis situations.
Official discussion
Organizations establish requirements for responding to incidents in incident response plans. Incorporating simulated events into incident response training helps to ensure that personnel understand their individual responsibilities and what specific actions to take in crisis situations.
Assessment objectives and methods
simulated events are incorporated into incident response training to facilitate the required response by personnel in crisis situations.
Examine
- Incident response policy
- procedures addressing incident response training
- incident response training curriculum
- incident response training materials
- incident response plan
- system security plan
- privacy plan
- other relevant documents or records
Interview
- Organizational personnel with incident response training and operational responsibilities
- organizational personnel with information security and privacy responsibilities
Test
- Mechanisms that support and/or implement simulated events for incident response training
IR-2(2) — Automated Training Environments
Provide an incident response training environment using [Organization-defined: automated mechanisms].
Official discussion
Automated mechanisms can provide a more thorough and realistic incident response training environment. This can be accomplished, for example, by providing more complete coverage of incident response issues, selecting more realistic training scenarios and environments, and stressing the response capability.
Organization-defined parameters (1)
Assessment objectives and methods
an incident response training environment is provided using [Organization-defined: automated mechanisms].
Examine
- Incident response policy
- procedures addressing incident response training
- incident response training curriculum
- incident response training materials
- automated mechanisms supporting incident response training
- incident response plan
- system security plan
- privacy plan
- other relevant documents or records
Interview
- Organizational personnel with incident response training and operational responsibilities
- organizational personnel with information security and privacy responsibilities
Test
- Automated mechanisms that provide a thorough and realistic incident response training environment
IR-2(3) — Breach
Provide incident response training on how to identify and respond to a breach, including the organization’s process for reporting a breach.
Official discussion
For federal agencies, an incident that involves personally identifiable information is considered a breach. A breach results in the loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or a similar occurrence where a person other than an authorized user accesses or potentially accesses personally identifiable information or an authorized user accesses or potentially accesses such information for other than authorized purposes. The incident response training emphasizes the obligation of individuals to report both confirmed and suspected breaches involving information in any medium or form, including paper, oral, and electronic. Incident response training includes tabletop exercises that simulate a breach. See [IR-2(1)](#ir-2.1).
Assessment objectives and methods
- IR-02(03)[01]incident response training on how to identify and respond to a breach is provided;
- IR-02(03)[02]incident response training on the organization’s process for reporting a breach is provided.
Examine
- Incident response policy
- contingency planning policy
- procedures addressing incident response testing
- procedures addressing contingency plan testing
- incident response testing material
- incident response test results
- incident response test plan
- incident response plan
- contingency plan
- system security plan
- privacy plan
- other relevant documents or records
Interview
- Organizational personnel with incident response training responsibilities
- organizational personnel with information security and privacy responsibilities
Authoritative sources
Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST. Official control requirements and interpretations remain with NIST and the responsible authorizing organization.