Beyond CMMC Level 1
The free web app covers the 17 CMMC Level 1 practices. This requirement is part of the full NIST 800-171 set — get the desktop app to work on all 110 requirements with SPRS scoring. Previously saved data is shown read-only below, and your data always remains exportable in full.
Get the desktop appSecurity Requirements for 03.06.03 Incident Response Testing
Organizations test incident response capabilities to determine the effectiveness of the capabilities and to identify potential weaknesses or deficiencies. Incident response testing includes the use of checklists, walk-through or tabletop exercises, simulations (both parallel and full interrupt), and comprehensive exercises. Incident response testing can also include a determination of the effects on organizational operations (e.g., reduction in mission capabilities), organizational assets, and individuals due to incident response.[SP 800-84] provides guidance on testing programs for information technology capabilities.
Assessment GuidanceExamine 0/11
How an assessor determines this requirement is met. Source: CMMC Assessment Guide – Level 2, Version 2.13 (NIST SP 800-171 Rev. 2).
Discussion
Testing incident response capability validates existing plans and highlights potential deficiencies. The test should address questions such as what happens during an incident;
who is responsible for incident management; what tasks are assigned within the IT organization; what support is needed from legal, public affairs, or other business components; how resources are added if needed during the incident; and how law enforcement is involved. Any negative impacts to the normal day-to-day operations when responding to an incident should also be identified and documented.
Examples
- Example 1
You decide to conduct an incident response table top exercise that simulates an attacker gaining access to the network through a compromised server. You include relevant IT staff such as security, database, network, and system administrators as participants. You also request representatives from legal, human resources, and communications. You provide a scenario to the group and have prepared key questions aligned with the response plans to guide the exercise. During the exercise, you focus on how the team executes the incident response plan. Afterward, you conduct a debrief with everyone that was involved to provide feedback and develop improvements to the incident response plan [a].
Assessment Methods
Not all of the evidence listed is required to meet this requirement — check the items your organization has collected.
- Personnel with incident response testing responsibilities
- Personnel with information security responsibilities
- Personnel with responsibilities for testing plans related to incident response
- Mechanisms and processes for incident response
Potential Assessment Considerations
- Does the incident response policy outline requirements for regular incident response plan testing and reviews of incident response capabilities [a]?