1Overview
IR.L2-3.6.3 closes the Incident Response family by proving the capability works. It requires that the organization test its incident response capability, so that the plan built under 3.6.1 is exercised and its gaps found before a real incident finds them. It is a one-point requirement with a single assessment objective, and it may be deferred on a plan of action.
A response capability that has never been tested is a set of assumptions, and incidents have a way of exposing the assumptions that do not hold. Testing, through exercises such as tabletop scenarios or more involved drills, reveals where roles are unclear, procedures do not fit reality, or resources are missing, while there is still time to fix them. This control asks the organization to test its incident response capability, turning a plan that looks good on paper into one that has been shown to work.
Test the organizational incident response capability.
The requirement is brief: test the capability. The form of the test can vary, from a tabletop walkthrough of a scenario to a fuller exercise, and what matters is that the capability is actually exercised so its readiness is confirmed and its gaps surfaced. Testing is what connects the plan of 3.6.1 to reality, and it is most useful when its findings feed back into improving the capability.
2The Assessment Objective
NIST SP 800-171A frames 3.6.3 as a single objective: test the incident response capability.
The incident response capability is tested. The organization exercises its incident response capability.
The single objective is testing the capability. The common failure is a plan that has never been exercised, so no one knows whether it would work. The assessor looks for evidence that the capability has been tested.
3Failure Patterns
The failures are about untested plans and tests that lead nowhere.
A plan never exercised
An incident response plan that has never been tested is a set of untested assumptions, and its gaps surface only during a real incident. Exercising it, even as a tabletop, is what the control requires.
No record of testing
A test conducted informally with nothing recorded cannot be demonstrated. Documenting the test shows it occurred and captures what it found.
Findings that go nowhere
A test that surfaces gaps but never leads to improvement wastes its value. The most useful testing feeds its findings back into the capability, though the control's core requirement is that the test happen.
4Ownership
This is a security-owned control, exercised with the people who would respond to a real incident.
| Role | Responsibility for this control |
|---|---|
| Security or compliance lead | Plans and conducts the test of the incident response capability and records it. Owns the test evidence. |
| IT and responders | Participate in the test as they would in a real incident, exercising their roles. |
| Leadership | Supports testing and acts on findings that call for resources or decisions. |
5Tooling
The control is delivered by incident response exercises and their records.
| Objective | Tooling | What it provides |
|---|---|---|
| test | Tabletop exercises, response drills | Exercise of the incident response capability. |
| record | Test records and after-action notes | Documentation that the test occurred and what it found. |
The caveat is that the test has to actually exercise the capability and be recorded. A tabletop that walks through a realistic scenario satisfies the control when documented, while an untested plan does not. The assessor examines evidence of testing, so a recorded exercise is what demonstrates the control.
6Evidence
The satisfied version of 3.6.3 shows the capability tested and recorded.
| Evidence | What it demonstrates |
|---|---|
| Test or exercise records | The objective. The incident response capability was tested. |
| After-action notes | The objective. Findings from the test, and any resulting improvements. |
The evidence should show that the incident response capability has been tested, with a record of the exercise. The test records, ideally with findings that fed back into the capability, are the clearest demonstration of the control.
An untested plan is a set of assumptions
A response capability that has never been exercised reveals its gaps only during a real incident, and this control asks for testing that surfaces them while there is still time to fix them. Running a tabletop exercise and feeding its findings back into the capability is part of the onsite readiness work this practice does.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.6.3. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objective 3.6.3. csrc.nist.gov
- 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov