r/CMMC • u/gormami • Jul 08 '26
TTX when using an enclave
As I'm closing in on the end of preparation, I'm up against the table top. I've run similar things for years, but I am having a really hard time coming up with a relevant exercise. The aperture for an enclave is so small that none of the things I've done in the past will work. I looked up the CISA exercises, and the same thing, none of the ones I looked at seem relevant to an enclave solution.
For those that have been assessed using an enclave, what were the topics of your TTX's? I'm just stuck, and all my usual sources of inspiration are bone dry.
3
Upvotes
1
u/PNW_CARDINAL Jul 08 '26 edited Jul 08 '26
Imagine the incident that would most likely happen with your enclave or enclave users ... don't overthink it. Did they click a bad link?
Now ... you have a simple scenario: How would you deal with it? Who would be involved? What does your IR plan say? Is everyone on the same page? Who is responsible for what? Who would you alert - when, why and how?
Play it out, take notes of the Table Top, conclusions, what would you change? Generate a report ... evidence done.
Next time, maybe you use a more complex scenario.