Skip to content
ControlVerdict
IR.L2-3.6.3addresses
IR.L2-3.6.3Incident Response Testing
Test the organizational incident response capability.
  • [a]

    the incident response capability is tested.

View full control

Two tabletops and one live containment drill a year, with findings that close

ControlVerdict Corpus@cv-corpusOSCJul 31, 2026
Community is just starting — add yours. No verdicts yet.

Implementation

AO coverage. Addresses the Incident Response Testing objective: the incident response capability is tested.

Annual test plan. Three exercises a year, scheduled in January so calendars are held: a spring tabletop with the technical responders, an autumn tabletop with the executive and contracts audience, and one live containment drill in a maintenance window. The plan states the objective of each exercise, who must attend, and what would constitute a failed exercise — which is what makes the result meaningful rather than a participation trophy.

Technical tabletop. Scenario driven from the library and rotated: ransomware on the file server, credential phishing of a contracts manager followed by mailbox rules, and a supplier-notified compromise of a shared engineering tool. Injects are timed and the facilitator withholds information deliberately, so the exercise tests decision-making under uncertainty rather than recall of the runbook.

Executive tabletop. Same scenario family, but the questions are the ones executives actually have to answer: do we notify the customer now or when we are certain, who talks to the press, who authorizes taking production offline, and what does the 72-hour clock mean for a discovery on a Friday night. The general counsel and the contracts lead attend.

Live drill. Once a year we do it for real on a volunteer endpoint: page on-call through the actual paging tool, isolate the host with the actual console, disable a test account, and restore a file from backup. This has repeatedly found the failures a tabletop cannot — an expired console permission, an on-call phone that had notifications muted, a restore path documented against a decommissioned tool.

Findings. Every exercise produces an after-action with findings assigned to owners with dates, tracked in the same register as assessment findings. The next exercise opens by reviewing the previous one's findings; unclosed items are read aloud, which is unsubtle and effective.

Maintenance. Scenario library refreshed annually against current threat reporting for our sector and against any real incident we experienced. New incident commanders run their first exercise as facilitator-supported.

Accepted gap. We have never tested with the managed detection provider participating live, because their exercise participation is billable and was cut from this year's budget. The next tabletop includes a simulated provider role played by the ISSO, and full participation is budgeted for next cycle.

What the evidence looks like

  • Annual exercise plan with dates, objectives, and required attendees
  • Two after-action reports with findings, owners, and due dates
  • Attendance records showing executive and contracts participation
  • Live drill log showing page, isolation, account disable, and restore timestamps
  • Finding register showing exercise findings closed with evidence

Environment

Manufacturer of ~180 staff. The incident response plan sat untested for two years; getting leadership into the room turned out to be harder than running the exercise.

Tools

Was this example useful?

Quick reaction — no account needed. For reasoning that moves the community meter, cast a full verdict below.

Discussion(0)

No discussion on this example yet

Verdicts capture a conclusion. Use a thread when the interesting part is the argument.

Sign in to start a thread.