Incident response exercise or drill
The shortest fixed clock in the held texts is 8,760 hours (yearly), set by PCI DSS 12.10.2. Paste one job that feeds this consumer, for example ir_tabletop_exercise, weekly, and the register reads its period against the clocks below, names the gap in hours, and carries the question for its owner.
Matched on the job name or the consumer column by these words: drill, tabletop, ir test, incident exercise, response exercise, exercise, ir exercise, response test, crisis exercise, tabletop exercise.
The clock each rule sets
| Regime | Clock | Clause |
|---|---|---|
| PCI DSS | 8,760h | PCI DSS 12.10.2 IRP reviewed and tested annuallyreviewed at least once every 12 months and tested annually |
| CPS 234 | 8,760h | CPS 234 para 32 Annual Review and Testing of Response Plansreviewed and tested annually |
| SP 800-53 | no clock | SP 800-53 IR-3 Incident response testinga defined frequency |
| ISO 22301 | no clock | ISO 22301 8.5 Exercise programmeplanned intervals |
| DORA | 8,760h | DORA Art. 25 Testing of ICT tools and systemsat least yearly |
| HIPAA | no clock | HIPAA 164.308(a)(7)(ii)(D) Testing and Revision Procedures (Addressable)periodic |
Questions this page answers
How often does PCI DSS v4.0 require incident response exercise or drill?
Yearly (8,760 hours): PCI DSS 12.10.2, IRP reviewed and tested annually. The incident response plan is reviewed at least once every 12 months and updated as needed, and tested annually.
How often does APRA CPS 234 require incident response exercise or drill?
Yearly (8,760 hours): CPS 234 para 32, Annual Review and Testing of Response Plans. Information security response plans must be reviewed and tested annually to confirm they remain effective and fit for purpose.
How often does NIST SP 800-53 Rev 5 require incident response exercise or drill?
The held text of SP 800-53 IR-3 (Incident response testing) sets no fixed period: a defined frequency. Requires the incident response capability serving the system to be tested for effectiveness at an organization-defined frequency using the test types the organization has defined, so readiness is demonstrated rather than assumed.
How often does ISO 22301:2019 require incident response exercise or drill?
The held text of ISO 22301 8.5 (Exercise programme) sets no fixed period: planned intervals. Implement and maintain a programme of exercising and testing that validates the effectiveness of the continuity strategies and solutions over time, running exercises and tests consistent with the continuity objectives, based on well planned scenarios with clearly defined aims, that build teamwork, competence, confidence and knowledge in those with response roles, that taken together over time validate the strategies and solutions, that produce formal post exercise reports with outcomes, recommendations and improvement actions, that are reviewed in the context of continual improvement, and that are held at planned intervals and when significant change occurs; act on the results to implement changes and improvements.
How often does DORA (Regulation (EU) 2022/2554) require incident response exercise or drill?
Yearly (8,760 hours): DORA Art. 25, Testing of ICT tools and systems. The testing programme shall include a range of assessments and tests (e.g. vulnerability assessments and scans, open-source analyses, network security assessments, gap analyses, physical security reviews, questionnaires, source-code reviews, scenario-based tests, compatibility/performance tests, end-to-end and penetration testing), with critical ICT systems tested at least yearly.
How often does HIPAA Security Rule require incident response exercise or drill?
The held text of HIPAA 164.308(a)(7)(ii)(D) (Testing and Revision Procedures (Addressable)) sets no fixed period: periodic. Implement procedures for periodic testing and revision of contingency plans. NIST recommends annual tabletop, biennial functional, and post-incident lessons-learned updates.
What does the register ask the owner of a incident response exercise or drill job?
Which on-demand packs does this exercise prove, and is the post-exercise report filed with the plan?
The clauses in full
The incident response plan is reviewed at least once every 12 months and updated as needed, and tested annually.
What an assessor asks to see: Annual IRP review minutes; Tabletop exercise reports; Lessons learned and IRP updates; Participant lists for exercises. Where it usually falls short: No annual test
Information security response plans must be reviewed and tested annually to confirm they remain effective and fit for purpose.
What an assessor asks to see: Annual review and test records for response plans; Exercise reports and resulting plan updates; Evidence of fitness for purpose conclusions. Where it usually falls short: Plans reviewed but never exercised
Requires the incident response capability serving the system to be tested for effectiveness at an organization-defined frequency using the test types the organization has defined, so readiness is demonstrated rather than assumed.
What an assessor asks to see: Defined test types and frequency for incident response testing; Exercise scenario documents and participant lists; Test reports with observations and identified weaknesses; Corrective actions tracked to closure after each test. Where it usually falls short: Only tabletop exercises run, so technical containment steps are never proven
Implement and maintain a programme of exercising and testing that validates the effectiveness of the continuity strategies and solutions over time, running exercises and tests consistent with the continuity objectives, based on well planned scenarios with clearly defined aims, that build teamwork, competence, confidence and knowledge in those with response roles, that taken together over time validate the strategies and solutions, that produce formal post exercise reports with outcomes, recommendations and improvement actions, that are reviewed in the context of continual improvement, and that are held at planned intervals and when significant change occurs; act on the results to implement changes and improvements.
What an assessor asks to see: Exercise programme showing scope, scenario and interval coverage over time; Exercise aims and objectives defined before each exercise; Formal post exercise reports with outcomes, recommendations and actions; Action tracking to closure with evidence of the resulting change. Where it usually falls short: The same comfortable scenario rehearsed annually, so rare failure modes are never stressed
The testing programme shall include a range of assessments and tests (e.g. vulnerability assessments and scans, open-source analyses, network security assessments, gap analyses, physical security reviews, questionnaires, source-code reviews, scenario-based tests, compatibility/performance tests, end-to-end and penetration testing), with critical ICT systems tested at least yearly.
What an assessor asks to see: Test plans and results across the required assessment types; At least-yearly testing of critical ICT systems. Where it usually falls short: Critical systems not tested annually
Implement procedures for periodic testing and revision of contingency plans. NIST recommends annual tabletop, biennial functional, and post-incident lessons-learned updates.
What an assessor asks to see: Test schedule; Test reports; After-action reports; Plan revision history. Where it usually falls short: Plans untested for years
Requirement text quoted from the standards themselves, published at compliance.theartofservice.com, the same publisher as this register, read against the held text of each standard: our statement of each clause, not the instrument verbatim. Run this job through the register