CHAPTER 8

Testing, Exercising, and Maintaining Plans

This chapter deals with various types of tests and exercises that an organization might undertake in order to validate the effectiveness of its plans. It also covers the process of reviewing the results of tests and exercises in order to maintain and improve the plans in readiness for responding to real incidents.

Testing and Exercising Plans

Let’s begin by examining the reasons why we need to test plans. An untested plan is not really a plan at all, as it lulls the organization into a false sense of security.

At first sight, the reason may appear to be obvious, but some organizations produce business continuity and disaster recovery plans and never actually test them, and their purpose is ...

Get Business Continuity in a Cyber World now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.