EXERCISE OBJECTIVES AND TRAINING AUDIENCE
CHAPTER 2
EXERCISE OBJECTIVES AND TRAINING AUDIENCE
EXERCISE OBJECTIVES
One of the first steps in the planning stage is to
determine the purpose and intended objectives
of the exercise. This must be logic-driven, based
on the exercise design chosen in the previous
step. Examples of core general exercise
objectives might include to:
practice technical skill;
train coordination and complex response
measures to cyber incidents;
grasp the broader national security
implications of a wide array of cyber
incidents;
practice communication and information
sharing with counterparts (other CERT
teams, media, private sector, law
enforcement bodies etc.);
practice reporting to managers and
decision-makers;
train teamwork (delegating, dividing and
assigning roles);
exercise
time
management
and
prioritization;
expose and validate cyber security/defense
policies and procedures;
experience work under stress and time
pressure;
gain deeper understanding of the
technical, political, strategic, diplomatic
and legal contexts of cyber crises;
improve the ability to convey the big
picture;
test a new organization, technology, tools,
processes and thereby reveal weak spots
and points of friction;
enhance cyber education and awareness at
all levels;
and many others.
The number of objectives should be balanced
to keep the exercise manageable. Objectives
can be broken down into main goals and ones
that are more specific. E.g. the main objective
of a technical exercise might be to test
technical capabilities, whereas the specific
training goals may be defined as training
incident handling processes, reporting to the
higher echelons, analyzing specific malwares,
conducting forensic investigation, writing
technical
analysis,
practicing
reverse
engineering, and so forth.
All objectives should be measurable. In other
words, they should be clearly defined, realistic,
reasonable, and in accordance with the
organization´s
visions,
principles,
competencies and current and future
challenges the organization faces. Where this
serves a purpose, a time limit should be set to
determine by when the tasks are to be
completed.
TRAINING AUDIENCE
In order to solve incidents rapidly and properly,
all relevant entities must be involved in
working towards the solution. Cooperation and
coordination across the security community
(horizontal perspective) is a key and
irreplaceable element in dealing with serious
incidents. In this regard, exercises offer an
excellent opportunity to establish or
strengthen relationships and trust. Cyberattacks (even if trivial on first sight) might
escalate, and stakeholders from various fields
might be affected as a consequence (as
indicated in Figure 3). Inviting representatives
from different spheres and sectors to the
exercise event creates opportunities for
effective future collaboration. Cooperation and
information sharing is used in real life to help
organizations better protect themselves
against cyber-attacks; cyber exercises
simulating those attacks should be treated the
same way.
9/29