17.7
IG2 IG3

Conduct Routine Incident Response Exercises

Asset Type: N/A
Security Function: Recover

Description

Plan and conduct routine incident response exercises and scenarios for key personnel involved in the incident response process to prepare for responding to real-world incidents. Exercises need to test communication channels, decision making, and workflows. Conduct testing on an annual basis, at a minimum.

Implementation Checklist

1
Define recovery objectives (RTO/RPO)
2
Implement recovery capabilities and procedures
3
Test recovery procedures on a regular schedule
4
Document recovery procedures and contact information
5
Develop incident response plan and playbooks
6
Define roles, escalation paths, and communication channels
7
Conduct tabletop exercise to validate plan
8
Establish post-incident review process
9
Draft policy/procedure document
10
Obtain stakeholder review and approval
11
Communicate to affected personnel
12
Schedule periodic review and updates

Threats & Vulnerabilities (CIS RAM)

Threat Scenarios

Ineffective Response to Real Incident Due to Untested Processes

Availability

During an actual ransomware attack, the incident response team fails to execute the documented plan effectively because they have never practiced it, resulting in missed steps and delayed containment.

Decision-Making Paralysis During First Real Incident

Availability

Key personnel freeze during a real security incident because they have never rehearsed decision-making under pressure, causing critical delays in containment and eradication.

Communication Breakdown During Incident Due to Untested Workflows

Availability

Incident response communication channels and escalation workflows fail during a real event because they were never tested through exercises, leaving responders unable to coordinate effectively.

Vulnerabilities (When Safeguard Absent)

No Incident Response Exercises Conducted

Without routine exercises such as tabletop scenarios, the incident response team has no practical experience executing the plan, identifying gaps in procedures, or testing communication channels under simulated pressure.

Untested Decision-Making and Escalation Workflows

Absence of exercises means decision-making processes, escalation paths, and inter-team coordination have never been validated, creating unknown failure points that surface during real incidents.

Evidence Requirements

Type Evidence Item Collection Frequency
Document Recovery plan documentation Reviewed annually
Record Recovery test results and lessons learned Tested quarterly
Document Incident response plan and playbooks Reviewed bi-annually
Record Incident reports and post-incident review documentation Per incident
Document Governing policy document (current, approved, communicated) Reviewed annually