Exercise Documentation
Each exercise record captures the date, exercise type, scenario description, participants and their roles, key findings from the exercise, and corrective actions with assigned owners and due dates. The scenario description is specific enough that an assessor can understand what was tested. not a one-line note that says "annual tabletop completed."
C3PAO assessors will ask to see exercise records and may conduct interviews with participants about what the exercise covered. 1TEN's records include the full participant list by name and role, and the scenario narrative. giving assessors the specificity needed to confirm a real exercise occurred and that personnel were actually involved.
Exercise Cadence and History
The exercise history view shows the full chronology of exercises conducted. dates, types, scenarios, and outcomes. For organizations conducting exercises annually, the history demonstrates that IR testing is an ongoing program rather than a one-time event. When an assessor asks "when was your last exercise and what did it cover," the answer is a dated record with a full scenario description, not a verbal recollection.
Corrective actions identified during exercises are tracked with owners and due dates. When a finding from an exercise results in a process change or a gap remediation, that follow-through is documented in the same record. The link between exercise findings and subsequent improvements is itself evidence of an effective IR testing program.
What You See Inside
- *Exercise record with date, type (tabletop, functional drill, full-scale simulation), and facilitator
- *Scenario description. what incident type was simulated, what the inject sequence covered
- *Participant list with name and role. the named personnel record assessors use to verify real participation
- *Findings section. gaps, process failures, or personnel confusion identified during the exercise
- *Corrective actions with assigned owner and due date. links findings to follow-on remediation
- *Pre-built scenario library. ransomware, phishing with CUI exfiltration, insider threat, physical breach, and supply chain compromise
- *Compliance Calendar integration. annual exercise scheduled and tracked as a recurring compliance task
- *Exercise history showing all exercises chronologically. demonstrates ongoing IR testing program
Pre-Built Scenario Types
| Scenario | What It Tests |
|---|---|
| Ransomware attack | Detection, containment, system isolation, recovery procedures, 72-hour reporting decision |
| Phishing with CUI exfiltration | Phishing identification, email quarantine, CUI exposure assessment, notification chain |
| Insider threat | Anomalous access detection, account suspension procedures, investigation workflow |
| Physical security breach | Physical access response, CUI exposure assessment, visitor log review, law enforcement notification |
| Supply chain compromise | Vendor notification, system isolation, contract review, flow-down implications |
| Lost or stolen portable media | Media inventory check, CUI exposure assessment, reporting obligations, encryption verification |
What this replaces
- *No exercise records at all. the most common state for IR.L2-3.6.3 and a guaranteed finding
- *A one-line calendar entry saying "tabletop exercise" with no scenario, no participant list, and no findings
- *Exercise findings noted verbally during the session and never documented. no corrective actions tracked, no follow-through demonstrated
- *No scenario library. exercises don't happen because no one takes ownership of writing and facilitating them
- *Exercise records stored outside the compliance program. a Word document in someone's folder that isn't linked to the IR requirements it satisfies
Practices Satisfied
| Practice ID | Description |
|---|---|
| IR.L2-3.6.3 | Test the organizational incident response capability. |
Related Modules
Every module ships on the 1TEN appliance. No configuration required. Schedule 30 minutes and see it running with your organization's data.