Newsletters Welcome, Guest Log In | Register


Join the Community

Exchange

Get full access to our community's expertise and resources.

Register Now >

Currently Being Moderated

Guide to Test, Training, and Exercise Programs for IT Plans and Capabilities

0

Created on: Sep 10, 2009 9:26 AM by NIST - Last Modified:  Sep 10, 2009 9:26 AM by NIST

Organizations have information technology (IT) plans in place, such as contingency and computer security incident response plans, so that they can respond to and manage adverse situations involving IT. These plans should be maintained in a state of readiness, which should include having personnel trained to fulfill their roles and responsibilities within a plan, having plans exercised to validate their content, and having systems and system components tested to ensure their operability in an operational environment specified in a plan. These three types of events can be carried out efficiently and effectively through the development and implementation of a test, training, and exercise (TT&E) program. Organizations should consider having such a program in place because tests, training, and exercises are so closely related. For example, exercises and tests offer different ways of identifying deficiencies in IT plans, procedures, and training.

This document provides guidance on designing, developing, conducting, and evaluating TT&E events so that organizations can improve their ability to prepare for, respond to, manage, and recover from adverse events that may affect their missions. The scope of this document is limited to TT&E events for single organizations, as opposed to large-scale events involving multiple organizations, involving internal IT operational procedures for emergencies. This document does not address TT&E for a specific type of IT plan; rather, the TT&E methodology described in this document can be applied to TT&E events built around any IT plan or around an IT emergency-handling capability that is not necessarily documented in a plan, such as computer security incident response.

The attached Zip file includes:

• Intro Page.doc

• Cover Sheet and Terms.pdf

• Guide to Test, Training, and Exercise Programs for IT Plans and Capabilities.pdf

Related Knowledge Network Content

Average User Rating
(0 ratings)




Add a comment Leave some feedback about this document.

There are no comments on this document

IT Manager Development Library

Learn all the basics of IT Management: budgeting, staff motivation, business planning and more with this unique eBook bundle.

Learn more >

Strategic IT Planning & Governance Best Practices Guide

Use this guide — along with the more than 60 templates included — to ensure the overall success of your entire IT department.

Learn more >

Application Grid

Learn more about this middleware layer that pools and dynamically provisions infrastruction application delivery resources to lower costs and improve efficiency.

Service Oriented Architecture (SOA)

Service-Oriented Architecture is the catalyst that allows today’s companies to respond to business demands faster and more effectively than ever.

Security Software Solutions

Security software and strategies to protect valuable company information and insure compliance with global, federal, and state regulations.

Application Performance Management

Application delivery and performance tools for Web applications to insure high availability and productivity.

Virtualization Strategy for Mid-sized Businesses

This white paper shows how mid-sized businesses can benefit by implementing the right virtualization solution.

Rethinking Storage Virtualization with the HP SAN Virtualization Services Platform

This white paper examines how a properly implemented virtualized storage infrastructure can enable you to meet business challenges while satisfying your data growth requirements — without injecting complexity into your infrastructure.