Incident Response Plan Tabletop Test Template
Learn how to successfully perform an IRP Tabletop Test
Written By Micah
What is an Incident Response Test?
An incident response test is a walkthrough of a realistic incident scenario against the documented steps in your Security Incident Response Plan (IRP or SIRP). The test results are often documented in a memo or ticket, and any refinements to the IRP as a result of the test should be incorporated back into the plan to improve its effectiveness.
How do I perform this control?
Performing an incident response tabletop is a similar process to performing a business continuity/disaster recovery tabletop test.
Brainstorm a realistic incident. For example, an executive losing their laptop in an airport or an employee responding to a phishing email and consequently sharing confidential information.
Have your incident response form or incident ticketing process handy and fill it out as you would in an actual incident. You may find that this form or process needs updating as well. It can also be used as evidence that you performed the test.
Have all participants sit around a table and then walk through your IRP, step by step. How does initial reporting of the incident work, what are the next steps, who will be involved etc. Have someone take notes or revise the IRP as the exercise occurs.
When finished, document the tabletop test in a document/memo or ticket noting when the tabletop was performed and who was involved. This ticket or document/memo will become the audit evidence you will upload to the Incident Response Tabletop Test evidence item.
If you identified anything about your IRP that you want to add or change because of the tabletop test, revise your IRP and upload the updated document to Strike Graph.
Why is this control important?
An annual incident response test allows the organization to refine the procedures that will take place to address an incident, and it's also an opportunity for key players in the process to practice responding to an incident.
Who’s involved with this control?
Typical control owner: Security Team Lead.
Typical participants: Anyone involved in responding to a hypothetical security incident. This depends somewhat on the nature of the hypothetical incident you're responding to, but usually the Security Team Lead, CISO, Head of IT, or CTO would be involved.
How often should I perform this control?
Organizations should test their incident response plan at least annually.
Tip: If your team documented and responded to a real incident within the last nine months, you can perform an after-action deep dive on your response to that incident in place of a hypothetical tabletop exercise. You should still upload a ticket or document/memo evidence to the Incident Response Tabletop Test evidence item for the auditors to review.