EXERCISE OBJECTIVES AND TRAINING AUDIENCE CHAPTER 2 EXERCISE OBJECTIVES AND TRAINING AUDIENCE EXERCISE OBJECTIVES One of the first steps in the planning stage is to determine the purpose and intended objectives of the exercise. This must be logic-driven, based on the exercise design chosen in the previous step. Examples of core general exercise objectives might include to:               practice technical skill; train coordination and complex response measures to cyber incidents; grasp the broader national security implications of a wide array of cyber incidents; practice communication and information sharing with counterparts (other CERT teams, media, private sector, law enforcement bodies etc.); practice reporting to managers and decision-makers; train teamwork (delegating, dividing and assigning roles); exercise time management and prioritization; expose and validate cyber security/defense policies and procedures; experience work under stress and time pressure; gain deeper understanding of the technical, political, strategic, diplomatic and legal contexts of cyber crises; improve the ability to convey the big picture; test a new organization, technology, tools, processes and thereby reveal weak spots and points of friction; enhance cyber education and awareness at all levels; and many others. The number of objectives should be balanced to keep the exercise manageable. Objectives can be broken down into main goals and ones that are more specific. E.g. the main objective of a technical exercise might be to test technical capabilities, whereas the specific training goals may be defined as training incident handling processes, reporting to the higher echelons, analyzing specific malwares, conducting forensic investigation, writing technical analysis, practicing reverse engineering, and so forth. All objectives should be measurable. In other words, they should be clearly defined, realistic, reasonable, and in accordance with the organization´s visions, principles, competencies and current and future challenges the organization faces. Where this serves a purpose, a time limit should be set to determine by when the tasks are to be completed. TRAINING AUDIENCE In order to solve incidents rapidly and properly, all relevant entities must be involved in working towards the solution. Cooperation and coordination across the security community (horizontal perspective) is a key and irreplaceable element in dealing with serious incidents. In this regard, exercises offer an excellent opportunity to establish or strengthen relationships and trust. Cyberattacks (even if trivial on first sight) might escalate, and stakeholders from various fields might be affected as a consequence (as indicated in Figure 3). Inviting representatives from different spheres and sectors to the exercise event creates opportunities for effective future collaboration. Cooperation and information sharing is used in real life to help organizations better protect themselves against cyber-attacks; cyber exercises simulating those attacks should be treated the same way. 9/29

Select target paragraph3