Control cross-reference
ISO/IEC 27001:2022 and your incident response exercise.
ISO/IEC 27001:2022 moved incident management into Annex A 5.24 to 5.30. The controls below are the ones an incident response exercise speaks to.
This is a cross-reference, not an assessment. Running an exercise does not by itself satisfy any control here. It produces a dated, attributed record, and your auditor decides what that record is worth against these criteria.
The controls
What an exercise speaks to.
-
A.5.24
Information security incident management planning and preparation
-
A.5.26
Response to information security incidents
-
A.5.27
Learning from information security incidents
-
A.5.29
Information security during disruption
-
A.5.30
ICT readiness for business continuity
The evidence
What a reviewer is actually asking for.
Not the plan. Almost everyone has a plan. They are asking whether it was exercised, when, by whom, and what that surfaced. That is a record with a date and people in it, and it only exists if the exercise actually happened.
Run one.
A live tabletop on your own systems and plan, with the record written by the time you finish, for $199.