Tabletop Exercise
What is Tabletop Exercise?
A discussion-based exercise where team members walk through simulated scenarios in a classroom setting. Tabletop exercises test incident response plans, business continuity procedures, and decision-making processes without activating real systems.
Frameworks that govern tabletop exercise
What the standards actually require on tabletop exercise
Requirements naming tabletop exercise across 6 standards, quoted from the control text.
Incident Response capability is critical per FSA Cybersecurity Guidelines. (1) Incident Response Plan: (a) Documented IR Plan + per FFIEC IT Examination Handbook reference; (b) ISO/IEC 27035 Information Security Incident Management;
JP-FSA-CYB-Incident-Response-Playbooks-Containment-Eradication-Recovery-Post-Mortem-Tabletop-CSIRT · Japan FSA Cybersecurity Incident Response + Playbooks + Containment + Eradication + Recovery + Post-Mortem + Tabletop Exercises + CSIRT + FSA Notification + Customer Communication + Forensics + Lessons Learned →Conduct tabletop exercises and technical drills at least annually covering realistic scenarios with internal and external stakeholders, including executive and legal participation.
PICERL-P-05 · Preparation: Tabletop Exercises and Drills →HKMA C-RAF Domain 3 PROTECTION + Domain 4 DETECTION. DOMAIN 3 PROTECTION (6 sub-areas): (1) ACCESS CONTROL - identity + access management + privileged access (PAM) + MFA + zero trust + just-in-time access + role-based access + access reviews + offboarding;
HKMA-CRAF-Domain3-4-Protection-Detection · HKMA C-RAF Domain 3 (Protection) + Domain 4 (Detection) - Access, Data, Infrastructure, Application, Monitoring, Testing, Threat Intel →Implement Systems Reliability Availability and Recoverability + Data Centre Resilience per MAS TRM Chapters 7 + 8. Chapter 7 Systems Reliability + Availability + Recoverability - Recovery Time Objective (RTO) definition + testing + Recovery Point Objective (RP...
MAS-TRM-Reliability-Data-Centre-Chapters-7-8-RTO-RPO-BCP-DR-System-Availability-4-Hours-12-Months · MAS TRM Reliability + Data Centre + Chapters 7-8 + RTO + RPO + BCP + DR + System Availability 4 Hours 12 Months →Operate recovery capability aligned with FIPS 199 impact level + NIST RMF integration per NIST SP 800-34 Rev 1 Appendix F (Sample Plans per Impact Level) + Chapter 4 (Information System Contingency Plan Development).
NISTSP34-8 · Recovery Capability by Impact Level, RTO/RPO, and Integration with NIST RMF →Conduct regular game days and tabletop exercises for credential compromise, ransomware and data breach scenarios to test plans, tools and team readiness.
SEC10-BP07 · Run simulations →Questions people ask about tabletop exercise
What is Tabletop Exercise?
Why is Tabletop Exercise important for compliance?
Which compliance frameworks address Tabletop Exercise?
Where can I learn more about Tabletop Exercise?
See how Tabletop Exercise applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.