FRAMEWORK GUIDES

What the rules actually require—without the legalese.

The regulations and standards that mandate exercise testing, explained in plain language, with the exercise obligation each one creates.

Last verified: September 2026

What ISO 27001 actually asks of your exercise program

What ISO/IEC 27001 asks of an exercise program, and what it doesn't. Why it is an information security management standard rather than an exercise mandate, the one conditional testing control in Annex A, the evaluation and improvement duties every ISMS carries, and why exercising still earns its place.

ISO 27001

Read the guide →

Last verified: September 2026

What NERC CIP-008 actually asks of your exercise program

What NERC CIP-008 asks of incident response testing, in the standard's own words. A mandatory test at least once every 15 calendar months, not annually; three acceptable methods, a tabletop exercise among them; which systems are in scope; what has to follow every test; why reporting is a separate duty; and where realistic exercises earn their place.

NERC CIP

Read the guide →

READINESS STARTS BEFORE THE CRISIS.

Put your team to the test.

Build your first scenario and turn preparation into measurable progress.

Explore pricing →Request a demo →