Incident response is one of the core business areas for a Security Operations Centre (SOC). Identifying vulnerabilities, threats, and attacks in progress are worth nothing unless the organization (informed by the SOC and others) does something about it.
There are national guidelines for identifying individual and team responsibilities during an incident response, but the 210-255 course centers around the American National Institute of Standards and Technology (NIST) guidelines. This is because Cisco is an American company, but also because the NIST guidelines are fairly internationally recognized as a baseline. National guidelines tend to supplement, rather than contradict, the NIST guidelines.
NIST has defined the stages of incident response (pre-, during-, and post-incident); the teams that exist and how they interact (national, company, industry...