CMMC Practice IR.L2-3.6.3 – Incident Response Testing: Test the organizational incident response capability.
Links to Publicly Available Resources
This document provides assessment guidance for conducting Cybersecurity Maturity Model Certification (CMMC) assessments for Level 2. This PowerPoint from Secureworks’ Security and Risk Consulting Incident Response (SRC-IR) Team discusses common tabletop exercise failures. This document from the IRS provides guidance for testing and exercising incident response capabilities. This paper provides an overview of the cyber exercise process from inception to reporting. This is a self-paced online training course regarding incident response offered by DHS. NIST resource that defines Incident Response testing requirements. This NIST Special Publication helps organizations in designing, developing, conducting, and evaluating test, training, and exercise events.
Discussion [NIST SP 800-171 R2]
Organizations test incident response capabilities to determine the effectiveness of the capabilities and to identify potential weaknesses or deficiencies. Incident response testing includes the use of checklists, walk-through or tabletop exercises, simulations (both parallel and full interrupt), and comprehensive exercises. Incident response testing can also include a determination of the effects on organizational operations (e.g., reduction in mission capabilities), organizational assets, and individuals due to incident response.
NIST SP 800-84 provides guidance on testing programs for information technology capabilities.
Further Discussion
Testing incident response capability validates existing plans and highlights potential deficiencies. The test should address questions such as what happens during an incident; who is responsible for incident management; what tasks are assigned within the IT organization; what support is needed from legal, public affairs, or other business components; how resources are added if needed during the incident; and how law enforcement is involved. Any negative impacts to the normal day-to-day operations when responding to an incident should also be identified and documented.