Guide to Test, Training, and Exercise Programs for IT Plans and Capabilities - Special Publication 800-84
BankInfoSecurity.com - Banking Information Security News, Regulations, & Education  

Username:
Password:
Agencies
Anti-Money Laundering
Business Continuity & Disaster Recovery
Compliance
Emerging Technology
Governance and Standards
Identity Theft
Leadership Management
Physical Security
Risk Management
Training & Education
Webinar Calendar
Vendor Directory
Content Library
Products
Events
About Us
Resources
 

Guide to Test, Training, and Exercise Programs for IT Plans and Capabilities - Special Publication 800-84

GuidanceNational Institute of Standards and Technology (NIST)Information Security
Risk Management

Organizations have information technology (IT) plans in place, such as contingency and computer security incident response plans, so that they can respond to and manage adverse situations involving IT. These plans should be maintained in a state of readiness, which should include having personnel trained to fulfill their roles and responsibilities within a plan, having plans exercised to validate their content, and having systems and system components tested to ensure their operability in an operational environment specified in a plan. These three types of events can be carried out efficiently and effectively through the development and implementation of a test, training, and exercise (TT&E) program. Organizations should consider having such a program in place because tests, training, and exercises are so closely related. For example, exercises and tests offer different ways of identifying deficiencies in IT plans, procedures, and training.

This document provides guidance on designing, developing, conducting, and evaluating TT&E events so that organizations can improve their ability to prepare for, respond to, manage, and recover from adverse events that may affect their missions. The scope of this document is limited to TT&E events for single organizations, as opposed to large-scale events involving multiple organizations, involving internal IT operational procedures for emergencies.

> Read entire regulation (log in required - registration is free)



Terms of Service | Advertise | Archive | Site Map | Contact | Bank Information Security RSS Syndication RSS Syndication
Copyright © 2007 BankInfoSecurity.com