Last verified: September 2026
What ISO 27001 actually asks of your exercise program
What ISO/IEC 27001 asks of an exercise program, and what it doesn't. Why it is an information security management standard rather than an exercise mandate, the one conditional testing control in Annex A, the evaluation and improvement duties every ISMS carries, and why exercising still earns its place.
ISO 27001
If your organisation runs an information security management system certified to ISO/IEC 27001, you have probably been told the standard wants your incident response tested on a set cycle, or an annual tabletop on the calendar.
It doesn't. ISO/IEC 27001 is an information security management system (ISMS) standard, not an exercise standard. No clause and no Annex A control requires an exercise or a test of your incident response, in any published account of the standard that we found. The one control that asks for testing is about ICT readiness for business continuity, and it applies only where your own risk treatment selects it.
What the standard does require of every conforming ISMS is harder to show with paperwork alone: that you evaluate whether your security is effective, and that you keep improving it. That is the better reason to exercise, and the second half of this guide makes that case. The first half is what the standard actually says.
How to read this guide. ISO/IEC 27001 is a copyrighted standard, sold by ISO and national standards bodies. The control statements in its Annex A come from a companion standard, ISO/IEC 27002, which is copyrighted too. Nothing on this page is quoted from either. Where we describe what a clause or control asks for, that is our characterisation, in our own words. It is cross-checked against certification bodies' published guidance and against the preview pages of both standards that are published free. We cite clause and control numbers and titles so you can find the text in your own copy. If you are implementing the standard, you need that copy.
Who this applies to
ISO/IEC 27001 is the international requirements standard for an ISMS. It covers setting one up, running it, keeping it current and improving it, including how you assess and treat information security risk.¹ It is written for organisations of every kind and size.¹
**It is a voluntary standard.**¹ Its requirements sit in Clauses 4 to 10. An organisation that claims to conform can't leave any of them out.¹ Annex A works differently, as the next section explains. Certification by an outside body is one way to demonstrate conformity. The standard itself says it can be used by parties inside or outside an organisation to judge whether the organisation meets its own security requirements.¹
| Your situation | What the standard means for you |
|---|---|
| Certified to ISO/IEC 27001 | Clauses 4 to 10 are requirements, audited at certification and through the certificate's life. Annex A controls apply as your Statement of Applicability records them.¹ ² |
| Claiming conformity without certification (for example, to a customer) | The same requirements apply for the claim to be true. Nobody audits them unless you or a customer arrange it.¹ |
| Using ISO/IEC 27001 as a reference only | No obligation. The standard is a benchmark you can choose to follow.¹ |
How Annex A binds: through your Statement of Applicability
This is the part most summaries skip, and it decides everything below.
You choose your controls through risk treatment, under Clause 6.1.3. You can design them yourself or take them from wherever you like. You then check them against Annex A, a reference catalogue of 93 controls, so that nothing necessary has been missed. Annex A is not a complete list, and it is **not a checklist you must implement in full.**¹ ²
The result is your Statement of Applicability. It records the controls you need and why, whether each is in place, and **why you excluded any Annex A control you didn't select.**¹ ² One certification body's guidance is blunt about the practical consequence: the statement has to address every Annex A control, and simply listing the ones you selected won't do.³
So "ISO 27001 requires control X" is only ever half a sentence. An Annex A control applies where your risk treatment makes it necessary, and your auditor assesses the justification if you exclude it.
Requirements at a glance
| What the standard asks, in substance | Where | Cadence | Exercise or test required? |
|---|---|---|---|
| An ISMS that is established, run, kept current and continually improved | Clauses 4–10¹ | — | No exercise named |
| Controls chosen through risk treatment, checked against Annex A and recorded in a Statement of Applicability, with exclusions justified | Clause 6.1.3, Information security risk treatment¹ ² | — | Not applicable |
| Incident management: preparing for incidents, assessing events, responding by your procedures, learning from real incidents, collecting evidence, reporting events | Annex A 5.24–5.28 and 6.8⁴ ⁵ ⁶ | — | No testing requirement in any published account we found |
| ICT readiness for business continuity, put in place, kept up and tested against your continuity objectives | Annex A 5.30, ICT readiness for business continuity, new in 2022⁴ ⁵ ⁶ ⁷ | None set | Yes, where 5.30 is in your Statement of Applicability. The form of the test isn't specified |
| Information security kept adequate while operations are disrupted | Annex A 5.29, Information security during disruption⁴ ⁶ ⁸ | — | Not settled. See Where the standard is deliberately open |
| Monitoring and measurement of the ISMS, and evaluation of its performance and effectiveness | Clause 9.1, Monitoring, measurement, analysis and evaluation¹ ³ ⁹ | When the organisation decides | Evaluation, not an exercise |
| Internal audit and management review | Clauses 9.2 and 9.3¹ ³ ⁹ | Planned intervals the organisation sets | Audit and review, not an exercise |
| Continual improvement, and correction of nonconformities | Clauses 10.1 and 10.2¹ | Ongoing | Improvement, not an exercise |
Our summary, not ISO's wording. Clause numbers and titles are from ISO's own contents pages. Annex A control titles are from ISO/IEC 27002:2022's contents page, whose controls Annex A carries.¹ ² ⁴ As of September 2026.
ISO 27001 is not an exercise standard
The incident controls ask you to be ready, not to rehearse. In substance, Annex A's incident-management controls ask for five things:⁵ ⁶
- 5.24 plan and prepare: roles, responsibilities and procedures for handling incidents
- 5.25 triage security events to decide which count as incidents
- 5.26 handle incidents by following your written procedures
- 5.27 feed what you learn from real incidents back into better controls
- 5.28 gather and safeguard evidence
Control 6.8 gives staff a prompt way to report what they see or suspect.⁶ None of the published accounts we found reads a testing or exercising requirement into any of them.
NIST's own mapping points the same way. NIST, the US National Institute of Standards and Technology, publishes an official crosswalk from its SP 800-53 security controls to ISO/IEC 27001:2022.¹⁰ Its incident response testing control, IR-3, reads: "Test the effectiveness of the incident response capability for the system [Assignment: organization-defined frequency] using the following tests: [Assignment: organization-defined tests]."
- In NIST's crosswalk, IR-3 maps to nothing in ISO/IEC 27001:2022: no clause and no Annex A control.¹⁰
- Neither do IR-3's three enhancements, nor NIST's control for building simulated events into incident response training.¹⁰
- NIST's incident response plan control maps to Annex A 5.24, and its incident handling control to 5.25–5.27. What finds no counterpart is the testing.¹⁰
If an incident-testing requirement sounds familiar, it may be because it is NIST's, not ISO's.
NIST attaches its own caution, and it belongs here: *"Organizations should not assume security requirement and control equivalency based solely on the mapping tables herein since there is always some degree of subjectivity in the mapping analysis because the mappings are not always one-to-one and may not be completely equivalent."*¹⁰ So the crosswalk corroborates the reading above. It doesn't replace it.
"Test" in an Annex A title rarely means an exercise. Controls 8.29, 8.31, 8.33 and 8.34 carry "test" in their titles.⁴ They are about security testing during development and acceptance, separating test environments, test information, and protecting systems during audit testing. None is about exercising your people.
The one testing touchpoint: Annex A 5.30
Annex A 5.30, ICT readiness for business continuity, is new in the 2022 edition⁴ ⁷ ⁸ and has no counterpart in 2013. In substance, it asks that your ICT be ready to support business continuity: put in place, kept up and tested against your continuity objectives and the ICT needs that flow from them.⁵ ⁷ Certification-body guidance builds it on a business impact analysis, with recovery time and recovery point objectives for the ICT that matters most.⁵ One certification body's transition checklist asks its assessors directly whether the IT requirements for business continuity have been tested.⁶
Three limits apply.
- It is conditional. Like every Annex A control, 5.30 applies where your risk treatment makes it necessary and your Statement of Applicability includes it. Excluding it takes a justification your auditor will look at.
- It sets no frequency and names no form of test. Nothing we found says how often, or whether "tested" means a technical recovery test, a walk-through or an exercise.
- It is ICT continuity, not incident handling. Its companion is Annex A 5.29, Information security during disruption, which folds together three 2013 continuity controls.⁶ ⁸ NIST maps its contingency-plan testing control to both 5.29 and 5.30.¹⁰ Neither is part of the incident-management set.
Whether a discussion-based exercise counts as testing under 5.30 isn't settled in any published account we found, so we don't claim it does. A discussion-based exercise tests decisions, coordination and the plan. It does not, on its own, prove that systems come back within their recovery objectives. That takes a technical recovery test.
Clauses 9 and 10: evaluation and improvement run through the whole ISMS
For a conforming organisation, these two clauses are requirements. Neither names an exercise.
- Clause 9.1 asks you to decide what to monitor and measure (your processes and controls among it), and how, when and by whom. You then judge how well the ISMS performs and whether it is effective. The 2022 edition adds that measurement should be consistent and repeatable enough to compare over time.³ ⁶ ⁹
- Clauses 9.2 and 9.3 ask for internal audit and management review at planned intervals you set yourself.³ ⁹ Certification-body guidance names three ways an ISMS's performance is evaluated: monitoring the effectiveness of controls, internal audit, and management review.³
- Clause 10 asks for continual improvement, and for nonconformities to be corrected. In the 2022 edition that is 10.1 and 10.2 respectively.¹ ²
"Planned intervals" belongs to audit and review, not to incident testing. The phrase governs internal audit, management review, risk assessment and policy review.⁴ ⁹ It isn't attached to incident management anywhere we found.
Why exercise anyway: what these duties actually ask of you
Everything above says ISO/IEC 27001 doesn't make you exercise. What it does ask for is an ISMS whose effectiveness you have evaluated and which you keep improving. For incident response, those two duties are hard to take seriously without exercising.
You can't genuinely evaluate a capability you have never seen work under pressure. Clause 9 asks whether your security is effective, and documents and audits answer part of that. They show that a procedure exists, that people know where to find it, and that last quarter's incidents were logged. They don't show whether your people can run the procedure at speed, with incomplete information, when the first two assumptions turn out to be wrong. That part of incident response doesn't show up in a document. It shows up under pressure.
Waiting for a real incident is the expensive way to learn. Annex A 5.27 asks you to learn from the incidents you have. Exercises let you learn before you have them: surface a gap in escalation, a missing decision owner or an untested assumption, and fix it while the cost is a conversation. That is continual improvement with an input, rather than improvement waiting for bad news.
Realistic, adaptive exercises are one of the most direct ways to generate that evidence and learning.
- A scripted walk-through tests whether the plan reads well. An adaptive exercise tests what your people decide when the situation responds to them.
- Each exercise produces a record of decisions, what worked and what didn't, and the actions that follow. That record helps generate the evidence your monitoring under 9.1, your management review under 9.3 and your improvement actions under Clause 10 draw on.
- Where your Statement of Applicability includes 5.30, an exercise built around an ICT disruption is designed to support the decisions and coordination behind ICT readiness. It works alongside the technical tests that prove systems recover, never instead of them.
Conformity comes from the whole system. Exercising is one of the most direct ways to make the evaluation and improvement that system asks for real.
What a certification audit looks at
This section describes certification as certification bodies and the accreditation rules describe it.² ³ ⁶ The standard that certification bodies themselves work to is separate and paywalled, and we haven't reviewed it.
- Your Statement of Applicability, complete. Every Annex A control addressed, selected or excluded, with a justification either way.³
- Implementation and effectiveness, not just documents. For the move to the 2022 edition, the accreditation rules told auditors to check the implementation and effectiveness of the new or changed controls an organisation chose, and not to rely on document review alone, especially for technological controls.²
- An internal audit programme across the whole cycle. One certification body expects every ISMS process to be audited over the three-year certification cycle, with higher-risk processes audited more often.³
- Management review on record, at planned intervals, with its decisions and actions.³
- Where 5.30 applies, whether ICT requirements for business continuity have been set and tested, including recovery objectives.⁶
- A three-year certificate, maintained through surveillance audits, with a new three-year period on recertification.⁷
What we won't tell you is what an individual auditor prefers: whether they want to see an incident exercise, how many, or of what type. None of that is written down in any published account we found. If you have been told it as a rule, ask where the rule is written.
ISO 27001 is not ISO 22301
The two are often discussed together, and they share a skeleton: both follow ISO's common structure for management system standards, with parallel headings in Clauses 4 to 10.¹ They are separate requirements standards, assessed separately.
Exercising is where they differ most. For a conforming organisation, ISO 22301, the business continuity standard, asks for a program of exercises in its Clause 8.5. ISO/IEC 27001 has no exercise-program clause. Its Clause 8 stops at 8.3.¹ Its nearest point of contact with business continuity is Annex A 5.29 and 5.30. The companion control guidance even takes its definition of "disruption" from ISO 22301.⁴
Two numbering traps.
- "Annex A 5.30" is a control, not "Clause 5.30". Clause 5 of ISO/IEC 27001 is Leadership.¹
- Nonconformity and corrective action is Clause 10.2 in ISO/IEC 27001:2022, not 10.1 as in ISO 22301.¹ Carry nothing across between the two without checking.
Which edition
ISO/IEC 27001:2022, the third edition, published in October 2022, is current as of September 2026. It replaced the 2013 edition.¹ ¹¹ It was amended in February 2024 by Amendment 1, Climate action changes, which is part of the current standard.¹¹
The 2013 edition is history, and so are its control numbers.
- Under the accreditation rules, **every certification to the 2013 edition expired or was withdrawn at the end of the transition period, 31 October 2025.**²
- The 2022 edition reorganised Annex A from 114 controls in 14 groups to 93 in four themes: organizational, people, physical and technological.² ⁴
- 2013's incident-management group was A.16, and its continuity group A.17.⁸ ¹² Certification-body mappings show 2013's event and weakness reporting merged into 6.8, its lessons-learned control carried into 5.27, and its three continuity controls folded into 5.29.⁶ ⁸
- If a policy, contract or vendor page still cites A.16.1.x or A.17.1.x, it is citing a withdrawn edition.
Where the standard is deliberately open
Naming these is more useful than papering over them. Your certification body may read them differently, and some turn on wording we don't reproduce.
- What "tested" covers in 5.30, and how often. Nothing we found specifies the form of test or a frequency. Your risk assessment and your auditor's reading will shape both.
- Whether 5.29 still asks you to verify your continuity arrangements, as its 2013 predecessors did. Certification-body guidance describes the 2022 control as clarifying and simplifying the old ones.⁶ Check your copy.
- Whether the companion guidance recommends exercising incident procedures. ISO/IEC 27002's guidance text isn't something we have reviewed. Even where guidance recommends something, it is guidance, not a requirement.⁸
- Whether a tabletop counts as testing under 5.30. No published account we found says, either way.
- Definitions are ISO's. ISO/IEC 27001 takes its vocabulary from ISO/IEC 27000.¹ Use your copy for what "test", "exercise" and "effectiveness" mean.
- Guidance on incident management and ICT readiness sits in other documents. The ISO/IEC 27035 series covers incident management, and ISO/IEC 27031:2025 covers ICT readiness for business continuity. Both are current as of September 2026.¹³ We haven't reviewed their contents for this guide.
What Crewcible produces that maps to it
Crewcible is built for the exercise itself: designing it, running it, and capturing what came out of it. Crewcible exercises are discussion-based. A discussion-based exercise pressure-tests the plan and the people; it doesn't prove your systems recover — that's what technical recovery testing is for. Within an ISMS that takes its evaluation and improvement duties seriously, three outputs line up.
Scenarios that put your incident response under pressure. Global Library scenarios are ready to run and can be launched in minutes. A scenario built for your own environment takes hours, not weeks. That makes it practical to exercise the incident your risk assessment actually worries about, rather than the one that is easiest to stage.
Exercises that follow your people, not a script. AI-suggested injects respond to what the crew actually decides, so the exercise tests judgement as the situation moves. The facilitator decides what gets released and when. AI enabled, human led.
A record you can improve from. Crewcible captures decisions and reasoning per participant and per inject as the exercise runs. After-action output and an improvement plan come out of the exercise, rather than being reconstructed a week later. That output is designed to support the evaluation and improvement work Clauses 9 and 10 ask of your ISMS, and it helps generate the evidence your management review works from. What you conclude from it, and what you change, stays your call.
Crewcible is built by experts who have supported crisis situations and exercises in the world's largest organizations.
For ready-to-run starting points, browse the Global Library and pick the disruption closest to the incidents your risk assessment ranks highest.
Standards references current as of September 2026. ISO/IEC 27001 and ISO/IEC 27002 content on this page is our characterisation, not a quotation of either standard. Quoted passages are NIST's text, verbatim. This guide is scheduled for re-verification by March 2027.
¹ ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection — Information security management systems — Requirements: ISO's official preview (cover, contents, foreword, introduction and Clauses 1 to 6.3), as distributed free by an ISO national member body. Clause numbers and titles are taken from its contents page. The foreword, introduction and Clauses 1 to 6.3 are paraphrased. Clause 9 onwards and Annex A are not in the preview.
² The accreditation system's mandatory transition requirements for ISO/IEC 27001:2022 (IAF MD 26:2023, issued February 2023). Used for the transition dates, the end of 2013 certification, the summary of changes, Annex A's role in risk treatment and the Statement of Applicability, and what a transition audit covered.
³ An accredited certification body's ISO 27001:2022 implementation guide. Secondary source. Used for the Statement of Applicability, performance evaluation, internal audit and management review.
⁴ ISO/IEC 27002:2022, Information security, cybersecurity and privacy protection — Information security controls: official preview, as distributed free by an ISO national member body. Used for Annex A control numbers and titles, taken from its contents page, and for its source note on the definition of "disruption". Control bodies are not in the preview.
⁵ A certification body's published commentary on Annex A 5.24 to 5.30 and on control 5.30 (the second, August 2024). Secondary sources, used to corroborate our characterisation of the incident and continuity controls.
⁶ The certification body in note 3: its ISO 27001:2022 gap analysis tool (February 2023), its assessor-facing checklist of 2022 changes. Secondary source. Used for Clause 9.1, controls 5.27, 5.29, 5.30 and 6.8, and the 2013-to-2022 mappings.
⁷ The same certification body's ISO 27001:2022 gap guide (June 2023). Secondary source. Used for Annex A 5.30 and the certification cycle.
⁸ A certification firm's explainer on ISO/IEC 27002:2022 (updated October 2023). Secondary source. Used for the 2013-to-2022 control mappings, 5.30 as a new control, and 27002 as guidance rather than requirements.
⁹ A national standards body's ISO/IEC 27001:2022 implementation guide. Secondary source. Used for Clauses 8 and 9 and where planned intervals apply.
¹⁰ NIST, SP 800-53 Rev. 5 to ISO/IEC 27001:2022 crosswalk (final, posted November 2023), listed among the SP 800-53 Rev. 5 supplemental materials. A mapping, not ISO's text. NIST's control wording and its caveat are quoted verbatim.
¹¹ ISO national member-body catalogue records: ISO/IEC 27001:2022 (edition, approval date, status, the edition it replaced and its amendment), and the standard's history, including the 2024 amendment and the 2013 edition's withdrawal.
¹² ISO/IEC 27002:2013, official preview, contents page only, for the 2013 control groups.
¹³ ISO national member-body catalogue records, for status only. Contents not reviewed: ISO/IEC 27035-1:2023, ISO/IEC 27035-2:2023 and ISO/IEC 27031:2025.