Batch Register

Incident response exercise or drill

The shortest fixed clock in the held texts is 8,760 hours (yearly), set by PCI DSS 12.10.2. Paste one job that feeds this consumer, for example ir_tabletop_exercise, weekly, and the register reads its period against the clocks below, names the gap in hours, and carries the question for its owner.

Matched on the job name or the consumer column by these words: drill, tabletop, ir test, incident exercise, response exercise, exercise, ir exercise, response test, crisis exercise, tabletop exercise.

The clock each rule sets

RegimeClockClause
PCI DSS8,760hPCI DSS 12.10.2 IRP reviewed and tested annuallyreviewed at least once every 12 months and tested annually
CPS 2348,760hCPS 234 para 32 Annual Review and Testing of Response Plansreviewed and tested annually
SP 800-53no clockSP 800-53 IR-3 Incident response testinga defined frequency
ISO 22301no clockISO 22301 8.5 Exercise programmeplanned intervals
DORA8,760hDORA Art. 25 Testing of ICT tools and systemsat least yearly
HIPAAno clockHIPAA 164.308(a)(7)(ii)(D) Testing and Revision Procedures (Addressable)periodic

Questions this page answers

How often does PCI DSS v4.0 require incident response exercise or drill?

Yearly (8,760 hours): PCI DSS 12.10.2, IRP reviewed and tested annually. The incident response plan is reviewed at least once every 12 months and updated as needed, and tested annually.

How often does APRA CPS 234 require incident response exercise or drill?

Yearly (8,760 hours): CPS 234 para 32, Annual Review and Testing of Response Plans. Information security response plans must be reviewed and tested annually to confirm they remain effective and fit for purpose.

How often does NIST SP 800-53 Rev 5 require incident response exercise or drill?

The held text of SP 800-53 IR-3 (Incident response testing) sets no fixed period: a defined frequency. Requires the incident response capability serving the system to be tested for effectiveness at an organization-defined frequency using the test types the organization has defined, so readiness is demonstrated rather than assumed.

How often does ISO 22301:2019 require incident response exercise or drill?

The held text of ISO 22301 8.5 (Exercise programme) sets no fixed period: planned intervals. Implement and maintain a programme of exercising and testing that validates the effectiveness of the continuity strategies and solutions over time, running exercises and tests consistent with the continuity objectives, based on well planned scenarios with clearly defined aims, that build teamwork, competence, confidence and knowledge in those with response roles, that taken together over time validate the strategies and solutions, that produce formal post exercise reports with outcomes, recommendations and improvement actions, that are reviewed in the context of continual improvement, and that are held at planned intervals and when significant change occurs; act on the results to implement changes and improvements.

How often does DORA (Regulation (EU) 2022/2554) require incident response exercise or drill?

Yearly (8,760 hours): DORA Art. 25, Testing of ICT tools and systems. The testing programme shall include a range of assessments and tests (e.g. vulnerability assessments and scans, open-source analyses, network security assessments, gap analyses, physical security reviews, questionnaires, source-code reviews, scenario-based tests, compatibility/performance tests, end-to-end and penetration testing), with critical ICT systems tested at least yearly.

How often does HIPAA Security Rule require incident response exercise or drill?

The held text of HIPAA 164.308(a)(7)(ii)(D) (Testing and Revision Procedures (Addressable)) sets no fixed period: periodic. Implement procedures for periodic testing and revision of contingency plans. NIST recommends annual tabletop, biennial functional, and post-incident lessons-learned updates.

What does the register ask the owner of a incident response exercise or drill job?

Which on-demand packs does this exercise prove, and is the post-exercise report filed with the plan?

The clauses in full

PCI DSS 12.10.2 IRP reviewed and tested annuallythe standard's page

The incident response plan is reviewed at least once every 12 months and updated as needed, and tested annually.

What an assessor asks to see: Annual IRP review minutes; Tabletop exercise reports; Lessons learned and IRP updates; Participant lists for exercises. Where it usually falls short: No annual test

CPS 234 para 32 Annual Review and Testing of Response Plansthe standard's page

Information security response plans must be reviewed and tested annually to confirm they remain effective and fit for purpose.

What an assessor asks to see: Annual review and test records for response plans; Exercise reports and resulting plan updates; Evidence of fitness for purpose conclusions. Where it usually falls short: Plans reviewed but never exercised

SP 800-53 IR-3 Incident response testingthe standard's page

Requires the incident response capability serving the system to be tested for effectiveness at an organization-defined frequency using the test types the organization has defined, so readiness is demonstrated rather than assumed.

What an assessor asks to see: Defined test types and frequency for incident response testing; Exercise scenario documents and participant lists; Test reports with observations and identified weaknesses; Corrective actions tracked to closure after each test. Where it usually falls short: Only tabletop exercises run, so technical containment steps are never proven

ISO 22301 8.5 Exercise programmethe standard's page

Implement and maintain a programme of exercising and testing that validates the effectiveness of the continuity strategies and solutions over time, running exercises and tests consistent with the continuity objectives, based on well planned scenarios with clearly defined aims, that build teamwork, competence, confidence and knowledge in those with response roles, that taken together over time validate the strategies and solutions, that produce formal post exercise reports with outcomes, recommendations and improvement actions, that are reviewed in the context of continual improvement, and that are held at planned intervals and when significant change occurs; act on the results to implement changes and improvements.

What an assessor asks to see: Exercise programme showing scope, scenario and interval coverage over time; Exercise aims and objectives defined before each exercise; Formal post exercise reports with outcomes, recommendations and actions; Action tracking to closure with evidence of the resulting change. Where it usually falls short: The same comfortable scenario rehearsed annually, so rare failure modes are never stressed

DORA Art. 25 Testing of ICT tools and systemsthe standard's page

The testing programme shall include a range of assessments and tests (e.g. vulnerability assessments and scans, open-source analyses, network security assessments, gap analyses, physical security reviews, questionnaires, source-code reviews, scenario-based tests, compatibility/performance tests, end-to-end and penetration testing), with critical ICT systems tested at least yearly.

What an assessor asks to see: Test plans and results across the required assessment types; At least-yearly testing of critical ICT systems. Where it usually falls short: Critical systems not tested annually

HIPAA 164.308(a)(7)(ii)(D) Testing and Revision Procedures (Addressable)the standard's page

Implement procedures for periodic testing and revision of contingency plans. NIST recommends annual tabletop, biennial functional, and post-incident lessons-learned updates.

What an assessor asks to see: Test schedule; Test reports; After-action reports; Plan revision history. Where it usually falls short: Plans untested for years

Requirement text quoted from the standards themselves, published at compliance.theartofservice.com, the same publisher as this register, read against the held text of each standard: our statement of each clause, not the instrument verbatim. Run this job through the register