Testing

Testing is the practice of validating that security controls work as intended and that the organization can withstand and respond to disruption. It replaces assumption with evidence, confirming that defenses perform under realistic conditions rather than only on paper.

Within the Preparation phase, testing is how readiness is proven before it is needed. Controls can be well designed yet fail in practice because of misconfiguration, gaps in coverage, or untested assumptions about how people and systems will behave. Testing surfaces these problems in a controlled setting, when there is time to fix them, instead of during a real incident.

In practice, testing spans several forms: tabletop exercises that walk teams through scenarios, technical validation that checks whether controls detect and block specific behaviors, and broader resilience assessments that stress critical processes. Purple-team exercises, where offensive and defensive efforts are deliberately paired, reveal both missed detections and gaps in response. Findings feed directly into improvement, closing gaps and refining plans. Regular, varied testing keeps readiness honest, ensuring that the capabilities an organization believes it has are the capabilities it can actually call on.

References#

  • NIST SP 800-84, Guide to Test, Training, and Exercise Programs
  • MITRE ATT&CK, adversary emulation guidance

Cookie Consent

We use cookies to enhance your experience. Learn more