5.1.5. Incident Response Training, Testing, and Evaluation
💡 First Principle: An experienced team's individual skill says nothing about whether the plan itself has gaps — stale contact lists, unclear authority, missing tool access — and only exercising the plan, not the people, surfaces those gaps before a real incident does.
Tabletop exercises (a walkthrough discussion of a simulated scenario) and full-scale simulations (executing actual technical response steps) test the plan's mechanics: does the on-call contact list still reach the right people, does the named incident commander actually have the system access their role requires, does the communication template still match current regulatory notification requirements. A team of highly skilled individual responders can still fail during a real incident if the plan around them — not their skill — has quietly gone stale since the last test.
| Exercise Type | Typical Cadence | What It Validates |
|---|---|---|
| Tabletop exercise | Quarterly | Decision-making, escalation, communication flow |
| Full-scale simulation | Annually | Technical response steps, tool access, timing |
| Contact list / on-call verification | Monthly | Whether the plan can actually reach the right people |
⚠️ Exam Trap: An experienced team is sometimes assumed to make plan testing less necessary. The correct answer recognizes that testing validates the plan itself — stale contact lists, unclear authority, missing tool access — which individual expertise doesn't reveal on its own.
Reflection Question: Your incident response team is highly experienced and has handled several real incidents well. Should this reduce how often you run tabletop exercises? What specifically would a tabletop exercise catch that real-world experience wouldn't?