IR-2 Incident Response Training

Description

Incident response training provided by organizations is linked to the assigned roles and responsibilities of organizational personnel to ensure the appropriate content and level of detail is included in such training.

For example:

  1. regular users may only need to know who to call or how to recognize an incident on the information system;
  2. system administrators may require additional training on how to handle/remediate incidents; and
  3. incident responders may receive more specific training on forensics, reporting, system recovery, and restoration.

Incident response training includes user training in the identification and reporting of suspicious activities, both from external and internal sources.

Applicability

This Control applies to the university Chief Information Security and Privacy Officer (CISPO) and or designees who are responsible for TAMU-CC University cybersecurity incident response.

Implementation

TAMU-CC provides incident response training to information system users consistent with assigned roles and responsibilities:

  1. Within 90 days of assuming an incident response role or responsibility;
  2. When required by information system changes; and
  3. Annually thereafter.

Revision History

Last Updated: February 21, 2025

Previous Versions:

  • June 29, 2023
  • May 31, 2022
  • March 25, 2021
  • September 16, 2019