Exercise and test programme
Which plans are exercised, how, how often, who takes part, and how the results change the plans.
How the register reads it
| Also called | tabletop exercises, DR test schedule |
|---|---|
| Family | Resilience and incidents |
| Document type | Record. The regimes ask for the content, not the label; a line pasted as a standard, procedure, plan or schedule is placed here with the label noted. |
| Folds into | The regimes accept it folded into the business continuity plan; when neither is listed, the gap is counted once, under the parent. |
| Expected owner | The business continuity manager or COO. |
| Review cadence | Annual: at least annually for each plan (the register's default; ISO 22301 8.5 asks for planned intervals and after significant change). |
| On the gap list when | ISO 22301 is ticked and no line resolves to it or to its parent (DORA requires it too, inside a parent document, so it does not list it separately). |
| Template | No template yet. The clauses below say what the document is expected to contain. |
Which standards require it, and what each expects it to contain
3 requiring clauses, 2 regimesShown on a register for the regimes you tick; with none ticked, ISO 27001 is applied. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.
ISO 22301:2019
ISO 22301 8.5 Exercise programmeImplement and maintain a programme of exercising and testing that validates the effectiveness of the continuity strategies and solutions over time, running exercises and tests consistent with the continuity objectives, based on well planned scenarios with clearly defined aims, that build teamwork, competence, confidence and knowledge in those with response roles, that taken together over time validate the strategies and solutions, that produce formal post exercise reports with outcomes, recommendations and improvement actions, that are reviewed in the context of continual improvement, and that are held at planned intervals and when significant change occurs; act on the results to implement changes and improvements.
Common gap: The same comfortable scenario rehearsed annually, so rare failure modes are never stressed
Source: ISO 22301:2019
ISO 22301 8.6 Evaluation of business continuity documentation and capabilitiesEvaluate whether the business impact analysis, risk assessment, strategies, solutions, plans and procedures remain suitable, adequate and effective, carrying out those evaluations through reviews, analysis, exercises, tests, post incident reports and performance evaluations, evaluating the continuity capabilities of relevant partners and suppliers, evaluating compliance with applicable legal and regulatory requirements and industry practice and conformity with the organization's own policy and objectives, and updating documentation and procedures promptly; conduct these evaluations at planned intervals, after an incident or activation, and when significant change occurs.
Common gap: Supplier continuity accepted on a self assessment questionnaire with nothing verified
Source: ISO 22301:2019
DORA (Regulation (EU) 2022/2554)
DORA Art. 24 General requirements for the performance of digital operational resilience testingFinancial entities shall establish, maintain and review a sound and comprehensive digital operational resilience testing programme as an integral part of the ICT risk management framework, following a risk-based approach.
Common gap: No resilience testing programme
Source: DORA (Regulation (EU) 2022/2554)
Do this for every document on your list
Paste the list and get this reading for every document at once, with the owner and cadence against each, the clauses quoted, and the documents the regimes expect that the list does not carry. Eight documents free, no account.
Build a registerEvidence collection and forensics procedure · Incident response plan