Kit · Assurance
Exercise & assurance kit
NIS2 requires policies and procedures to assess the effectiveness of the risk-management measures. Effectiveness, not existence — which makes this a testing obligation, and the SOC is where the test happens.
- Cadence
- Quarterly
- Output
- Findings with owned actions
Three kinds of test, for three kinds of question
| Test | Answers | Cost |
|---|---|---|
| Atomic technique test | Does this specific detection fire when this specific behaviour occurs? | Low — can be run continuously |
| Table-top exercise | Do the people know what to do, and do the decision paths actually work? | Medium — a few hours of the right people |
| Purple team engagement | Would we catch a capable adversary working towards an objective? | High — but the only one that tests the chain end to end |
Running a table-top exercise
The point is to find the decisions nobody has made, not to demonstrate that the team is competent.
Detection efficacy testing
Prove that the detection stack still does what your coverage map claims it does.
Four failure points, four different fixes
No telemetry means a collection problem. Telemetry but no rule fire means a content problem. Rule fired but no alert reached anyone means a routing or suppression problem. Alert reached someone who did nothing means a procedure or workload problem. Reporting these as one number — “we detected 7 of 12” — hides which of the four you need to fix.
Next kit
Board communication kit
The arguments that land with a management body, the numbers to bring, and how to ask for resource in terms of accepted risk.