Security Training

Dispatches · Standards

CISA, NIST and the SEC: the public sources behind a cyber exercise program

Field note

Four public sources cover most of what a US-focused cyber exercise program needs. CISA's Tabletop Exercise Packages supply ready-made exercises. NIST SP 800-84 explains how to design and evaluate a test, training and exercise program. NIST SP 800-61 Rev. 3 describes what good incident response looks like, which tells you what to test. The SEC's 2023 rules explain why boards of public companies now ask for the evidence.

Editorial assessment · Assessed from vendor sites, product pages and published pricing, September 2026

By Security Training assessors · 15 April 2026

8-1CISA Tabletop Exercise Packages: the materials

CISA publishes over 100 Tabletop Exercise Packages (CTEPs). Each includes objectives, scenarios, discussion questions and references, plus a slide deck, a feedback form and an after-action report template. Cyber scenarios cover ransomware, insider threats, phishing and industrial control system compromise, with sector versions.

Use them as the starting point for a first exercise, or as a benchmark for a platform: whatever you buy should produce an exercise and a report at least as useful as a package you could adapt yourself. Our six-step guide shows how to run one.

8-2NIST SP 800-84: the program

NIST SP 800-84, published in September 2006, is NIST's guide to test, training and exercise (TT&E) programs for IT plans and capabilities. It treats exercises as a program of events that test plans, train staff and exercise procedures, and it covers designing, conducting and evaluating those events. It predates today's platforms, but its structure still fits: plan the events, run them, evaluate them against objectives, and feed the lessons back into the plans.

Our lessons on discussion-based vs operations-based exercises and building an annual exercise program draw on it.

8-3NIST SP 800-61 Rev. 3: what to test

NIST SP 800-61 Rev. 3, published in April 2025, is NIST's incident response guidance, written as a Community Profile of the Cybersecurity Framework (CSF) 2.0. It places incident response inside the organization's wider cybersecurity risk management rather than treating it as a standalone technical process.

For an exercise program, that shift matters. Objectives should test governance decisions, such as who declares an incident and who approves disclosure, as well as detection and containment. The lesson on writing exercise objectives shows how to turn those decisions into objectives an evaluator can grade.

8-4The SEC's 2023 rules: why the board asks

The SEC adopted its cybersecurity disclosure rules on 26 July 2023. Form 8-K Item 1.05 requires US public companies to disclose a material cybersecurity incident, generally within four business days of determining it is material. Regulation S-K Item 106 requires an annual description of the processes for managing material cybersecurity risk, the board's oversight of that risk, and management's role.

Two consequences for exercising. The materiality determination is a decision with a deadline attached, so it is worth rehearsing; our materiality article has a session plan. And exercise records are among the few artefacts that show the Item 106 processes in use.

8-5How do the four fit together?

  • Why: the SEC rules, and the board's oversight duty, set the reason and the audience for the evidence.
  • What to test: NIST SP 800-61 Rev. 3 describes the incident response capabilities and decisions worth testing.
  • How to run the program: NIST SP 800-84 gives the structure for planning, conducting and evaluating exercises.
  • What to use: CISA's packages give free, ready-made exercises and report templates.

Organizations outside the US, or in regulated sectors, will add their own sources. Vendors on this site name frameworks such as DORA, NIS2, ISO 27001, ISO 22301 and APRA CPS 230; the lesson on mapping exercise evidence to frameworks covers how to use those mappings.

Sources

  1. CISA Tabletop Exercise Packages: https://www.cisa.gov/resources-tools/services/cisa-tabletop-exercise-packages
  2. NIST SP 800-84: https://csrc.nist.gov/pubs/sp/800/84/final
  3. NIST SP 800-61 Rev. 3: https://csrc.nist.gov/pubs/sp/800/61/r3/final
  4. SEC press release 2023-139: https://www.sec.gov/newsroom/press-releases/2023-139