last sync: 2024-Nov-25 18:54:24 UTC

Microsoft Managed Control 1355 - Incident Response Training | Regulatory Compliance - Incident Response

Azure BuiltIn Policy definition

Source Azure Portal
Display name Microsoft Managed Control 1355 - Incident Response Training
Id 90e01f69-3074-4de8-ade7-0fef3e7d83e0
Version 1.0.0
Details on versioning
Versioning Versions supported for Versioning: 0
Built-in Versioning [Preview]
Category Regulatory Compliance
Microsoft Learn
Description Microsoft implements this Incident Response control
Additional metadata Name/Id: ACF1355 / Microsoft Managed Control 1355
Category: Incident Response
Title: Incident Response Training - Frequency
Ownership: Customer, Microsoft
Description: The organization provides incident response training to information system users consistent with assigned roles and responsibilities: at least annually thereafter.
Requirements: All Microsoft personnel receive refresher training on security on an annual basis as part of their regular security awareness training. Service team on-call personnel receive additional training on their incident management roles and responsibilities through exercises and actual incident handling. Security Response Team members respond to incidents daily and commonly hold various industry certifications which require annual Continuing Professional Education (CPE) credits. Employees with security-relevant roles receive refresher training on security on an annual basis, as part of their regular security training. Service team and feature team on-call personnel receive additional, in-place, training on their incident management roles and responsibilities through mandatory exercises conducted annually.
Mode Indexed
Type Static
Preview False
Deprecated False
Effect Fixed
audit
RBAC role(s) none
Rule aliases none
Rule resource types IF (2)
Microsoft.Resources/subscriptions
Microsoft.Resources/subscriptions/resourceGroups
Compliance
The following 1 compliance controls are associated with this Policy definition 'Microsoft Managed Control 1355 - Incident Response Training' (90e01f69-3074-4de8-ade7-0fef3e7d83e0)
Control Domain Control Name MetadataId Category Title Owner Requirements Description Info Policy#
op.exp.7 Incident management op.exp.7 Incident management 404 not found n/a n/a 103
Initiatives usage
Initiative DisplayName Initiative Id Initiative Category State Type
Spain ENS 175daf90-21e1-4fec-b745-7b4c909aa94c Regulatory Compliance GA BuiltIn
History none
JSON compare n/a
JSON
api-version=2021-06-01
EPAC