ISO 22301:2019
Operation, ISO 22301:2019

ISO 22301:2019 8.5: Exercise programme

Put in place and keep up a programme of exercises and tests that shows, over time, that the continuity strategies and solutions work. The exercises and tests must: fit the continuity objectives; rest on carefully planned scenarios with clearly stated aims; build teamwork, competence, confidence and knowledge among those who have roles in the response; together, over time, confirm the strategies and solutions; lead to formal reports after each exercise setting out outcomes, recommendations and improvement actions; be reviewed with continual improvement in mind; and take place at planned intervals and whenever significant change happens. Act on what they show by making changes and improvements.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 88 controls across 36 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 12 controls

ISO 19011:2018 · 6 controls

  • 5.4 Establishing the audit programme
  • 5.4.1 Roles and responsibilities of the individual(s) managing the audit programme
  • 5.4.3 Establishing extent of audit programme
  • 5.5 Implementing audit programme
  • 5.6 Monitoring audit programme
  • 5.7 Reviewing and improving audit programme

ISO 27001:2022 · 6 controls

  • 5.24 Information security incident management planning and preparation 
  • 5.26 Response to information security incidents
  • 5.29 Information security during disruption
  • 5.30 ICT readiness for business continuity
  • 5.36 Compliance with policies, rules and standards for information security
  • 5.5 Contact with authorities
  • NIST-CSF-GV.OV-03 Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed
  • NIST-CSF-ID.IM-01 Improvements are identified from evaluations
  • NIST-CSF-ID.IM-03 Improvements are identified from execution of operational processes, procedures, and activities
  • NIST-CSF-ID.RA-08 Processes for receiving, analyzing, and responding to vulnerability disclosures are established
  • NIST-CSF-PR.IR-03 Mechanisms are implemented to achieve resilience requirements in normal and adverse situations
  • NIST-CSF-RS.MA-01 The incident response plan is executed in coordination with relevant third parties once an incident is declared

ISO 27002:2022 · 4 controls

  • 5.24 Information security incident management planning and preparation
  • 5.26 Response to information security incidents
  • 5.30 ICT readiness for business continuity
  • 6.3 Information security awareness, education and training

CIS Controls v8 · 3 controls

  • CIS-11.5 Test Data Recovery
  • CIS-17.7 Conduct Routine Incident Response Exercises
  • CIS-18.1 Establish and Maintain a Penetration Testing Program

FedRAMP High · 3 controls

  • CP-4 Contingency Plan Testing
  • CP-4(1) Coordinate with Related Plans
  • IR-3(2) Incident Response Testing | Coordination with Related Plans (IR-3(2))

FedRAMP Moderate · 3 controls

  • CP-4 Contingency Plan Testing
  • CP-4(1) Coordinate with Related Plans
  • IR-3(2) Incident Response Testing | Coordination with Related Plans (IR-3(2))

HIPAA Security Rule · 3 controls

NIST SP 800-66 Rev 2 · 3 controls

PCI DSS 4.0 · 3 controls

  • 12.10.2 12.10.2 Annual review and testing of the incident response plan
  • 12.10.6 12.10.6 Plan evolved from lessons learned and industry developments
  • 12.3.1 12.3.1 Targeted risk analysis for flexible-frequency requirements

SOC 2 · 3 controls

  • SOC2-A1.3 A1.3 Testing recovery plan procedures
  • SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16)
  • SOC2-CC7.4 CC7.4 Responding to security incidents
  • A.2.8 A.2.8 Test and validate the plan
  • A.2.9 A.2.9 Training for response teams
  • ASD37-34 Regular backups (Essential)
  • ASD37-35 Business continuity and disaster recovery plans (Very Good)
  • CFTC-SS-11 Testing and Review of Business Continuity and Disaster Recovery Capabilities
  • CFTC-SS-28 Synchronised Testing with Members and Market Participants

CMMC 2.0 · 2 controls

NIST SP 800-161 Rev 1 · 2 controls

  • E8-BACKUP-ML1 Regular Backups (ML1)
  • A.8.3 A.8.3 Exercises and testing with formal post-exercise reports

APRA CPS 234 · 1 control

  • CPS234-32 Annual Review and Testing of Response Plans
  • AEO-12 Crisis Management and Incident Recovery

C5 (Germany) · 1 control

  • C5-BCM-04 Verification, updating and testing of the business continuity

COBIT 2019 · 1 control

  • DSS04.04 DSS04.04 Exercise, test and review the business continuity plan (BCP) and disaster response plan (DRP)

ISO 22000:2018 · 1 control

  • 8.5 Hazard control
  • ISO-22313-8.5 Exercise programme

ISO 27701:2019 · 1 control

  • 8.5 PII sharing, transfer, and disclosure

ISO 28002:2011 · 1 control

  • A.6.3.2 A.6.3.2 Exercises and testing

ISO 37001:2016 · 1 control

  • 8.5 8.5 Implementation of anti-bribery controls by controlled organizations and by business associates

ISO 9001:2015 · 1 control

  • 8.5 Production and service provision

ISO/IEC 38500:2024 · 1 control

  • 4.1.2 Effective performance

NIST SP 800-172 · 1 control

  • 3.2.2e Practical Exercises in Awareness Training

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Operation, ISO 22301:2019

You are reading one control. How much of ISO 22301:2019 have you already done?

ISO 22301:2019 8.5 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 22301:2019 your existing evidence covers. Hold APRA CPS 230 Operational Risk Management and 28 of 57 ISO 22301:2019 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the APRA CPS 230 Operational Risk Management pair alone.

Query this from an agent

The graph holds this control, the 88 it maps to, and the evidence behind each claim, over MCP and REST.