The organization tests and evaluates whether its resilience policy, programmes, processes and procedures, including supply chain partnerships and relationships, are appropriate and effective, validating the policy through exercises and tests that: fit the scope and objectives of the system; are based on the risk assessment and well planned with clear aims and objectives; keep low the chance that operations are disrupted or assets harmed; end with a formal report of results, recommendations and actions to put improvements in place on time; are reviewed to support continual improvement; and are run at intervals set by management, sometimes unannounced, and whenever the organization or its environment changes significantly. Annex B adds scenarios drawn from the risk assessment, stated objectives (capacity, speed, awareness), lessons from earlier tests and real incidents, assigned responsibility, a schedule that grows from checklists to full activation with external services, critical evaluation of results and documentation.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.