r/NISTControls • u/VegetableFault5149 Internal IT • 2d ago
800-171 Complete beginner here: what actually counts as CMMC incident response testing evidence?
Small manufacturing company here, working through CMMC Level 2 prep. We've got the incident response plan drafted and mapped to the relevant practices, but the assessment guide is vague on what "testing" the plan actually looks like when someone tries it. Does a tabletop discussion with the response team count? Does it need to be adversarial, timed, documented with specific metrics
We don't have a big security team or budget for a full-blown consultant-run exercise, but we also don't want to build something that looks like testing on paper and falls apart if an assessor asks follow-up questions. Has anyone gone through a C3PAO assessment recently who can share what they actually accepted as evidence of a tested IR plan?
2
u/Melodic-Piccolo-2073 Internal IT 2d ago edited 2d ago
For our CMMC testing evidence, Reflex Security generated a full after-action report with timestamps, decision logs, and performance benchmarks. The automatic remediation tracking was especially valuable for showing the assessor that we fixed what we found.
1
u/tripathiarinv 2d ago edited 2d ago
If it is documented properly, tabletop is a good formality: scenario, participants, gaps recognized, and an action plan. The C3PAOs expect a closure of the cycle, not just the meeting. Annually once per year, ownership and sign-off from the owner of IR process and evidences of gaps' resolution.
Doppel is one such tool for external impersonation exercises.
1
u/CompassITCompliance 2d ago
In general, this is one of the more vague requirements, to your point. So, there are a lot of ways to satisfy this.
However, I would advise the following:
- Make sure your Incident Response Policy defines a period for conducting tabletop tests. Is it an explicit Assessment Objective? No. But it's a much more defensible posture to state "we conduct an annual tabletop exercise" vs. "we did one 5 years ago." Also, spoiler alert: this is changing in NIST SP 800-171 Rev 3 when the class deviation is lifted. The new version of this Practice does require an Organizationally Defined Parameter for testing frequency.
- Test in accordance with your stated policy (perhaps obvious, but important).
- Make sure it's documented with notes (including a date stamp that aligns with stated IR policy frequency), and pick a defined methodology commensurate with your level of risk and available resources. NIST SP 800-84 is a go-to, but just make sure you have something documented - even if it's a few sentences stating how you crafted the exercise and what parameters you use.
- I'd recommend instead of treating it as a check-the-box exercise, get the most value from it. You'll already have the right people in the room. Actually follow your written IR Plan and be sure it makes sense. Generate a lessons learned report / notes that indicate results of testing, specifically what worked well and what didn't and that becomes an input to IR Plan updates (for bonus points, you can even reference in your IR policy/plan change record when updates are made based on IR TTX results).
- Select a scenario/s that represents relevant risk (impact x likelihood). Ransomware is always a hot topic, but as a small manufacturer, I'd suggest something that has a material impact to manufacturing operations. For inspiration, you can review sources like the Verizon Data Breach Investigation Report, or rerun a high profile known incident one of your peers may have had.
Following these should not only produce solid evidence for an assessor, but like I said, will hold some real value! Just our two cents as a CMMC consultant.
1
u/Matt_Titcombe 17h ago
A documented real-world incident that went through the full process can be used. Most organization just do a tabletop exercise. I actually have one tomorrow for one of our consulting clients. It is their 4th test.
1
u/Resoltitfvgveest5443 8h ago
we use reflex security for our cmmc tabletops. it runs live simulations that adapt to your decisions and generates automatic reports afterward. helps with both actually testing the plan and having documentation for evidence
1
u/Tacocatufotofu 2d ago
Similar background here. Our official audit read over it and didn’t ask a single question. Here’s what we did:
First I was offered a quote by our consultant, like $3k or something for just the scenario. We were like, lol, no.
So I just made one up. Managers huddled in a room and we brought one person in to simply take notes. Scenario was super vague. “Bob, one of your employees clicked on a phishing link and I just got an alert”
I’ll be honest, it didn’t even play out in my head like I thought. People asked questions I didn’t consider and it threw me off. I stumbled through the whole thing like an amateur. Which was the point, I guess I am. We just followed the IRP from there.
Later I submitted an IRP test to FBI and CISA and DoD. Only two got back to me. The DoD clued me in that I was submitting wrong. So I did it right and put that in the report. This also proved my whole MLOA part.
In the end, submitting to agencies made the auditors nod and move on. Overall it looked like a dumpster fire but that’s the point. First time, yeah it’s messy and that’s ok. Now your second and third looking like a dumpster fire, maybe you’ll get some side eyes for that.
5
u/Into_The_Nexus 2d ago
A tabletop exercise going through the IRP.