Exercise and test business continuity and operational resilience plans at least annually or upon significant changes.
Exercises and tests should include but are not limited to:
a. Processes established in the business continuity plan.
b Alignment with business continuity policies.
c. Critical systems and equipment relevant to the business continuity plan.
d. Roles and responsibilities of the various parties involved in the exercises.
e. The use of CSP support mechanisms in CSC exercises.
f. A review and update of communication templates.
g. Lessons learned from previous events and exercises.
h. Tabletop exercises.
Depending on the level of CSP maturity, the CSP’s practices may include automated chaos testing.
Exercise and test business continuity and operational resilience plans at least annually or upon significant changes.