Incident Response & Operations

IR Exercises Tabletop · Drill Documentation · Findings Tracking

IR.L2-3.6.3 requires testing your incident response capability. not just having one. The IR Exercises module creates the dated, structured exercise records that prove your IR program is tested, not just written.

IR.L2 3.6.3 satisfied
Scenario Library included
Dated Exercise history
The problem this solves
IR.L2-3.6.3 is one of the three IR practices required for CMMC Level 2, and it is the one contractors most often leave unsatisfied. Having an incident response plan satisfies 3.6.1. Reporting incidents satisfies 3.6.2. Testing the capability is a third, separate requirement. and "we would do a tabletop if we had an incident" does not satisfy it. Assessors verify this practice by looking for dated exercise records with participants, scenarios, and findings. If the records don't exist, the practice is not met.

Exercise Documentation

Each exercise record captures the date, exercise type, scenario description, participants and their roles, key findings from the exercise, and corrective actions with assigned owners and due dates. The scenario description is specific enough that an assessor can understand what was tested. not a one-line note that says "annual tabletop completed."

C3PAO assessors will ask to see exercise records and may conduct interviews with participants about what the exercise covered. 1TEN's records include the full participant list by name and role, and the scenario narrative. giving assessors the specificity needed to confirm a real exercise occurred and that personnel were actually involved.

Dashboard Requirements Evidence POA&M Reports
1TEN Incident Response tabletop exercises interface with scenarios, participants, and after-action records

Exercise Cadence and History

The exercise history view shows the full chronology of exercises conducted. dates, types, scenarios, and outcomes. For organizations conducting exercises annually, the history demonstrates that IR testing is an ongoing program rather than a one-time event. When an assessor asks "when was your last exercise and what did it cover," the answer is a dated record with a full scenario description, not a verbal recollection.

Corrective actions identified during exercises are tracked with owners and due dates. When a finding from an exercise results in a process change or a gap remediation, that follow-through is documented in the same record. The link between exercise findings and subsequent improvements is itself evidence of an effective IR testing program.

What You See Inside

  • *Exercise record with date, type (tabletop, functional drill, full-scale simulation), and facilitator
  • *Scenario description. what incident type was simulated, what the inject sequence covered
  • *Participant list with name and role. the named personnel record assessors use to verify real participation
  • *Findings section. gaps, process failures, or personnel confusion identified during the exercise
  • *Corrective actions with assigned owner and due date. links findings to follow-on remediation
  • *Pre-built scenario library. ransomware, phishing with CUI exfiltration, insider threat, physical breach, and supply chain compromise
  • *Compliance Calendar integration. annual exercise scheduled and tracked as a recurring compliance task
  • *Exercise history showing all exercises chronologically. demonstrates ongoing IR testing program

Pre-Built Scenario Types

Scenario What It Tests
Ransomware attackDetection, containment, system isolation, recovery procedures, 72-hour reporting decision
Phishing with CUI exfiltrationPhishing identification, email quarantine, CUI exposure assessment, notification chain
Insider threatAnomalous access detection, account suspension procedures, investigation workflow
Physical security breachPhysical access response, CUI exposure assessment, visitor log review, law enforcement notification
Supply chain compromiseVendor notification, system isolation, contract review, flow-down implications
Lost or stolen portable mediaMedia inventory check, CUI exposure assessment, reporting obligations, encryption verification

What this replaces

  • *No exercise records at all. the most common state for IR.L2-3.6.3 and a guaranteed finding
  • *A one-line calendar entry saying "tabletop exercise" with no scenario, no participant list, and no findings
  • *Exercise findings noted verbally during the session and never documented. no corrective actions tracked, no follow-through demonstrated
  • *No scenario library. exercises don't happen because no one takes ownership of writing and facilitating them
  • *Exercise records stored outside the compliance program. a Word document in someone's folder that isn't linked to the IR requirements it satisfies

Practices Satisfied

Practice IDDescription
IR.L2-3.6.3 Test the organizational incident response capability.

Related Modules

Incident Response
Exercises use the same incident lifecycle structure as real incidents. personnel practice the same workflow they'll follow when it counts.
Compliance Calendar
Annual IR exercise is scheduled and tracked in the Compliance Calendar. overdue exercises surface before they become an assessment finding.
Policy Generator
The IR policy generated by the Policy Generator defines roles and procedures that exercises validate. findings from exercises can drive policy updates.
Evidence Manager
Exercise records are uploaded to the Evidence Manager and linked to IR.L2-3.6.3. ready for assessor review without searching for the file.
See IR Exercises in action.

Every module ships on the 1TEN appliance. No configuration required. Schedule 30 minutes and see it running with your organization's data.

Request a demo