Requirements / Incident Response (IR)
IR.L2-3.6.3
Incident Response Testing
Official Source Material
Test the organizational incident response capability.
Determine if:
- [a] the incident response capability is tested.
Source: CMMC Assessment Guide - Level 2, Version 2.13, September 2024
Practitioner Guidance
How to meet it
A tabletop exercise once a year carries this requirement.
Gather the people named in the incident response plan, walk a realistic scenario end to end, and take notes. The requirement text sets no frequency, but a test with no recurrence goes stale as systems and people change. A plan that exists only on paper is exactly what this requirement exists to catch. An annual exercise keeps the evidence current and the muscle memory real.
Test the plan you actually wrote.
Drive the scenario through your own procedures. Cover how the incident is discovered, who is called, which forms get filled in, how containment is decided, and who talks to the prime contractor and to DoD. Fill out your real incident forms during the exercise. Walk the reporting steps for DIBNET, DoD's incident reporting portal, without submitting. Check whether your logs would have caught the scenario's activity. Every gap you find is the test working.
A real incident does not replace a deliberate test.
The requirement's discussion names checklists, walk-through and tabletop exercises, simulations, and comprehensive exercises as testing. Fold what a real response taught you into the plan, and still run the exercise, because a live incident exercises only the path it happened to take.
No special people or tools are needed.
Your own administrators are the ones who will respond to a real incident, so they are the right people to test with. A conference room, a scenario, and two hours does it. CISA, the federal cybersecurity agency, publishes free tabletop exercise packages with ready-made scenarios if you do not want to write your own.
The output documents are the evidence.
Keep the scenario, the date, the attendee list, notes on what worked and what did not, and the changes made to the plan afterward. A lessons-learned item that produced an actual change is the strongest answer to [a], because it shows the test changed something.
What falls short
- An incident response plan with no test on record. A reviewed and signed plan shows the plan exists, not that the capability was tested, so [a] has no evidence.
- A write-up of a real incident offered as the test. It supplements testing without replacing the deliberate exercise the requirement's discussion describes, so [a] is not evidenced.
Edge cases
- When an MSP or MSSP, a managed service provider or managed security service provider, performs your incident response, they belong in the exercise. A test that never engages the people who would actually respond does not test the capability.