Tabletop Exercise:
Definition: Discussion-based event where personnel with roles and
responsibilities in an IT department meet in a classroom setting or in
breakout groups to discuss their roles and responsibility during a
security event incident situation.
Duration: 2 hours to 8 hours depending on the audience, the topic
being exercised, and the exercise objectives.
Benefits of Tabletop exercise:
Evaluate & Validate CSIRT preparedness.
Coordinated decision making.
Strengthen crisis preparedness.
Design Considerations for a Tabletop Exercise:
Identify the Topic Ransomware
Determine the scope Based on target audience (Roles &
Responsibilities) ISS CSIRT team & COOP.
Identify Objectives Validate CSIRT, Policies & Procedures,
Agency Interdependencies etc.
Identify Participants Facilitator (leading the exercise), Data
Collector (Records Information), Players (Assist Data Collector),
Support Staff (Technical support).
Conduct the exercise Conf room, participant guide, exercise
debrief.
Evaluate the result Prepare after action report, brief mgmt.
Tabletop Lifecycle:
Step1: Prepare & Plan
Step4: Improve Step2: Conduct Exercise
Cybersecurity Program
Step3: Identify Lessons
Learned