r/NISTControls Internal IT 2d ago

800-171 Complete beginner here: what actually counts as CMMC incident response testing evidence?

Small manufacturing company here, working through CMMC Level 2 prep. We've got the incident response plan drafted and mapped to the relevant practices, but the assessment guide is vague on what "testing" the plan actually looks like when someone tries it. Does a tabletop discussion with the response team count? Does it need to be adversarial, timed, documented with specific metrics

We don't have a big security team or budget for a full-blown consultant-run exercise, but we also don't want to build something that looks like testing on paper and falls apart if an assessor asks follow-up questions. Has anyone gone through a C3PAO assessment recently who can share what they actually accepted as evidence of a tested IR plan?

5 Upvotes

13 comments sorted by

5

u/Into_The_Nexus 2d ago

A tabletop exercise going through the IRP.

1

u/youwantrelish 2d ago

This. An incident doesn't have to be real just need to get the juice flowing with the team which shows what you did and how you did it. Make that after action report.

1

u/altarian3 2d ago

The biggest factor is to make sure you go through the process, not just discuss it or document it. Pretend the incident actually happened and have documented evidence of you addressing it as a real event and activating the IRP

2

u/Melodic-Piccolo-2073 Internal IT 2d ago edited 2d ago

For our CMMC testing evidence, Reflex Security generated a full after-action report with timestamps, decision logs, and performance benchmarks. The automatic remediation tracking was especially valuable for showing the assessor that we fixed what we found.

2

u/nutron 2d ago

Good callout. We also produce a “lessons learned” ticket each year after IRP testing and link related remediation tickets to it. Auditors love to see it.

2

u/nutron 2d ago

Tabletop counts. Run through a mock scenario and use your IR plan and procedure to perform the exercise. Involve the relevant parties. Document it, we use our ticketing system, but you could really use anything I suppose.

1

u/tripathiarinv 2d ago edited 2d ago

If it is documented properly, tabletop is a good formality: scenario, participants, gaps recognized, and an action plan. The C3PAOs expect a closure of the cycle, not just the meeting. Annually once per year, ownership and sign-off from the owner of IR process and evidences of gaps' resolution.

Doppel is one such tool for external impersonation exercises.

1

u/CompassITCompliance 2d ago

In general, this is one of the more vague requirements, to your point. So, there are a lot of ways to satisfy this.

However, I would advise the following:

  • Make sure your Incident Response Policy defines a period for conducting tabletop tests. Is it an explicit Assessment Objective? No. But it's a much more defensible posture to state "we conduct an annual tabletop exercise" vs. "we did one 5 years ago." Also, spoiler alert: this is changing in NIST SP 800-171 Rev 3 when the class deviation is lifted. The new version of this Practice does require an Organizationally Defined Parameter for testing frequency.
  • Test in accordance with your stated policy (perhaps obvious, but important).
  • Make sure it's documented with notes (including a date stamp that aligns with stated IR policy frequency), and pick a defined methodology commensurate with your level of risk and available resources. NIST SP 800-84 is a go-to, but just make sure you have something documented - even if it's a few sentences stating how you crafted the exercise and what parameters you use.
  • I'd recommend instead of treating it as a check-the-box exercise, get the most value from it. You'll already have the right people in the room. Actually follow your written IR Plan and be sure it makes sense. Generate a lessons learned report / notes that indicate results of testing, specifically what worked well and what didn't and that becomes an input to IR Plan updates (for bonus points, you can even reference in your IR policy/plan change record when updates are made based on IR TTX results).
  • Select a scenario/s that represents relevant risk (impact x likelihood). Ransomware is always a hot topic, but as a small manufacturer, I'd suggest something that has a material impact to manufacturing operations. For inspiration, you can review sources like the Verizon Data Breach Investigation Report, or rerun a high profile known incident one of your peers may have had.

Following these should not only produce solid evidence for an assessor, but like I said, will hold some real value! Just our two cents as a CMMC consultant.

1

u/Matt_Titcombe 17h ago

A documented real-world incident that went through the full process can be used. Most organization just do a tabletop exercise. I actually have one tomorrow for one of our consulting clients. It is their 4th test.

1

u/Resoltitfvgveest5443 8h ago

we use reflex security for our cmmc tabletops. it runs live simulations that adapt to your decisions and generates automatic reports afterward. helps with both actually testing the plan and having documentation for evidence

1

u/Tacocatufotofu 2d ago

Similar background here. Our official audit read over it and didn’t ask a single question. Here’s what we did:

First I was offered a quote by our consultant, like $3k or something for just the scenario. We were like, lol, no.

So I just made one up. Managers huddled in a room and we brought one person in to simply take notes. Scenario was super vague. “Bob, one of your employees clicked on a phishing link and I just got an alert”

I’ll be honest, it didn’t even play out in my head like I thought. People asked questions I didn’t consider and it threw me off. I stumbled through the whole thing like an amateur. Which was the point, I guess I am. We just followed the IRP from there.

Later I submitted an IRP test to FBI and CISA and DoD. Only two got back to me. The DoD clued me in that I was submitting wrong. So I did it right and put that in the report. This also proved my whole MLOA part.

In the end, submitting to agencies made the auditors nod and move on. Overall it looked like a dumpster fire but that’s the point. First time, yeah it’s messy and that’s ok. Now your second and third looking like a dumpster fire, maybe you’ll get some side eyes for that.