Periodically test, update, and verify the effectiveness of incident response plans using various event scenarios. For critical operations, plans should be tested at least annually. Test results should be documented and communicated—with follow-up action plans developed as appropriate.
Incident response plans should be reconciled with the organization's business continuity and disaster recovery plans.
Organizations should also test, update, and improve incident response plans after:
a. Significant organizational changes.
b. External supply chain disruptions and natural disasters.
c. Security attacks, particularly those resulting in security breaches.
Test and update as necessary incident response plans at planned intervals or upon significant organizational or environmental changes for effectiveness.