BCR-10: Is the disaster response plan exercised annually or when significant changes
occur?
The plan should be executed at regular intervals based on the organization’s BIA. It should be performed as a tabletop exercise and incorporate an annual live event with local authorities (e.g., fire departments, health officials, police departments, anti-terrorist organizations, and anti-cybercrime groups).
Depending on regulatory requirements, the business, and the industry, a disaster recovery (DR) exercise might be required. For example, financial institutions may consider running live on DR for extended periods or simulate component or partial failures to test overall organizational resiliency and recovery abilities.
Control implemented
Control ownership
Description
Exercise the disaster response plan annually or upon significant
changes, including if possible local emergency authorities.
Response Plan Exercise
BCR-10: Are local emergency authorities included, if possible, in the exercise?
The plan should be executed at regular intervals based on the organization’s BIA. It should be performed as a tabletop exercise and incorporate an annual live event with local authorities (e.g., fire departments, health officials, police departments, anti-terrorist organizations, and anti-cybercrime groups).
Depending on regulatory requirements, the business, and the industry, a disaster recovery (DR) exercise might be required. For example, financial institutions may consider running live on DR for extended periods or simulate component or partial failures to test overall organizational resiliency and recovery abilities.
Control implemented
Control ownership
Description
Exercise the disaster response plan annually or upon significant
changes, including if possible local emergency authorities.