Source | Azure Portal | ||||||||||||||||||||||
Display name | Microsoft Managed Control 1356 - Incident Response Training | Simulated Events | ||||||||||||||||||||||
Id | 8829f8f5-e8be-441e-85c9-85b72a5d0ef3 | ||||||||||||||||||||||
Version | 1.0.0 Details on versioning |
||||||||||||||||||||||
Versioning |
Versions supported for Versioning: 0 Built-in Versioning [Preview] |
||||||||||||||||||||||
Category | Regulatory Compliance Microsoft Learn |
||||||||||||||||||||||
Description | Microsoft implements this Incident Response control | ||||||||||||||||||||||
Additional metadata |
Name/Id: ACF1356 / Microsoft Managed Control 1356 Category: Incident Response Title: Incident Response Training | Simulated Events Ownership: Customer, Microsoft Description: The organization incorporates simulated events into incident response training to facilitate effective response by personnel in crisis situations. Requirements: Service teams include Red Team exercises as part of incident management training. Red Team exercises are intended to identify weaknesses in the existing incident management processes. Incident tests and exercises are considered in-place training and are used to support other onsite training for new personnel with incident roles. Service teams include tabletop and functional exercises as part of incident management training. Part of the training replicates a real incident and walks personnel through the incident management process. Additionally, incident management tests and exercises are considered in-place training and are used to support other onsite training for new employees and other support staff with incident roles. Personnel are not made aware that they are being tested during incident management tests. As part of the service team-specific incident management procedures, each team provides additional information and training to provide an understanding of the team’s distinct responsibilities and accountabilities in support of incident management. The Security Response Team uses job shadowing of real and red team incidents due to the centralized nature of the incident management function in Azure and the availability of job-shadowing within the Security Response Team. Live, ongoing, on the job training provides a more thorough and realistic security incident management training environment by indoctrinating all stakeholders with the incident management procedures in real time. Azure considers job shadowing of live incidents a preferred and more effective alternative to simulated training mechanisms. As part of the service team-specific incident management procedures, each team provides additional information and training to provide an understanding of the team’s distinct responsibilities and accountabilities in support of incident management. |
||||||||||||||||||||||
Mode | Indexed | ||||||||||||||||||||||
Type | Static | ||||||||||||||||||||||
Preview | False | ||||||||||||||||||||||
Deprecated | False | ||||||||||||||||||||||
Effect | Fixed audit |
||||||||||||||||||||||
RBAC role(s) | none | ||||||||||||||||||||||
Rule aliases | none | ||||||||||||||||||||||
Rule resource types | IF (2) Microsoft.Resources/subscriptions Microsoft.Resources/subscriptions/resourceGroups |
||||||||||||||||||||||
Compliance |
The following 1 compliance controls are associated with this Policy definition 'Microsoft Managed Control 1356 - Incident Response Training | Simulated Events' (8829f8f5-e8be-441e-85c9-85b72a5d0ef3)
| ||||||||||||||||||||||
Initiatives usage |
|
||||||||||||||||||||||
History | none | ||||||||||||||||||||||
JSON compare | n/a | ||||||||||||||||||||||
JSON |
|