Security Training

University · Evidence and programs · Lesson 10

How to map cyber exercise evidence to frameworks and regulations

Field note

A framework mapping links an exercise's objectives and findings to the controls or requirements they test. It is a claim, not a certificate: your auditor or supervisor decides what counts. Keep five records from every exercise, map them to the frameworks you report against, and ask vendors to show the mapping in a sample report rather than a slide.

Editorial assessment · Assessed from vendor sites, product pages and published pricing, September 2026

By Security Training assessors · 9 September 2026

L10-1What does a mapping actually do?

A mapping says which requirement an exercise tested. An objective such as 'the incident commander declares a severity level within the target time' tests an incident response control. If the exercise record shows the objective, the result and the follow-up, it becomes evidence that the control operates. The mapping is the index that lets an auditor find it.

L10-2Which frameworks do vendors name?

The vendors in this guide name different frameworks on their public pages, which reflects who they sell to.

  • iluminr: DORA, ISO 22301, APRA CPS 230, FCA/PRA, NIST CSF, UK operational resilience, ISO 27001, FFIEC and OSFI E-21.
  • Reflex Security: reports mapped to SOC 2, ISO 27001 and DORA.
  • Immersive Labs: evidence against frameworks such as NIS2 and DORA; in March 2026 it announced heat maps for NIST CSF, NIST NICE, MITRE ATT&CK, D3FEND and ATLAS, and GRC content for ISO 27001, ISO 42001 and SOX.
  • TryHackMe: tabletop scenarios aligned to NIST and ISO 27035.
  • Cyberbit: its crisis simulation page references NIST and the CREW framework.

A long list is not better by itself. What matters is whether the platform maps to the frameworks you are assessed against, and at what level of detail.

L10-3Which records count as evidence?

  1. The exercise plan: scenario, objectives and the plan or playbook sections under test.
  2. Attendance: who played which role, and who was absent.
  3. The decision log: what was decided, by whom, when and on what information.
  4. The after-action report, with each objective graded and each gap tied to an owner and a date.
  5. Remediation tracking: proof that the gaps were closed, and the date each one was retested.

The fifth record is the one most often missing. An auditor who sees the same gap in two consecutive reports will ask why.

L10-4How does this apply to SEC disclosure?

US public companies must describe, in their annual report, their processes for assessing, identifying and managing material cybersecurity risk and the board's oversight of that risk (Regulation S-K Item 106). Exercise records are one of the few artefacts that show those processes in use. Our article on rehearsing the materiality decision sets out a session plan.

L10-5What should you ask a vendor?

  • Show me a sample report with the mapping in it, not a list of logos.
  • Is the mapping to named controls or clauses, or to the framework as a whole?
  • Who maintains the mapping when a framework is revised?
  • Can we export the evidence into our GRC tool or audit file?

Our Evidence criterion (weight 16) scores what an exercise leaves behind. iluminr scores 9 there, the highest in the set; see the rankings for the others.

Sources: sec.gov/newsroom/press-releases/2023-139, csrc.nist.gov/pubs/sp/800/61/r3/final, cisa.gov/resources-tools/services/cisa-tabletop-exercise-packages · Reviewed Sep 2026

Next lesson: How to build an annual cyber exercise program