Testing IR plans
The effectiveness of an IR team can best be determined through battle testing, at least once annually, as advised by NIST SP 880-61r2
: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf. This involves putting it into use in a simulated environment or a test failure or attack. The goal is to get the response team acquainted with using the plan to resolve incidents and also to discover and rectify gaps in the plan. Therefore, when testing the plan, the following should be considered:
- The ability of each team member to follow the outlined procedures
- The bottlenecks experienced in the plan
- The time taken to contain an incident, if successful
- The causes of failure to contain an incident, if unsuccessful
The outcomes of each test should be used for the improvement of both the plan and the IR team. If team members are having a hard time following the outlined procedures, the organization should either retrain...