9.1 Exercise Programme Design & Governance
Key Takeaways
- ISO 22301:2019 Clause 8.5 mandates the implementation and maintenance of a comprehensive exercise and testing programme to validate business continuity strategies, capabilities, and plans over time.
- Exercising evaluates human decision-making, procedural coordination, and command structures, whereas testing validates the technical and physical functionality of systems, facilities, and equipment.
- ISO 22398 provides the international benchmark for exercise programme management, establishing a multi-year progressive lifecycle from simple discussions to complex full-scale simulations.
- Exercise objectives must be SMART (Specific, Measurable, Achievable, Relevant, Time-bound) and directly linked to Business Impact Analysis (BIA) metrics, including RTO, RPO, and MBCO.
- Exercise safety and risk management require strict operational boundaries, designated Safety Officers, unambiguous communication prefixes ('EXERCISE ONLY'), and universal abort mechanisms ('No Play' / 'Code Red') to prevent exercise-induced disruptions.
Exercise Programme Design & Governance
A Business Continuity Management System (BCMS) documented solely on paper provides an illusion of resilience. Plans that have never been rehearsed, communication chains that have never been activated, and recovery solutions that have never been stressed inevitably fail when subjected to the chaotic conditions of a real-world disaster. ISO 22301:2019 Clause 8.5 (Exercising and testing) establishes the non-negotiable requirement that an organization must implement, maintain, and continually evaluate an exercise and testing programme to validate its continuity strategies, solutions, and procedures over time.
To establish a mature, audit-compliant exercise capability, Lead Implementers must look to ISO 22398:2013 (Societal security — Guidelines for exercises), which provides the foundational governance architecture, lifecycle methodology, and execution principles for designing exercises that systematically elevate organizational competence without introducing unmanaged operational risks.
1. ISO 22301 Clause 8.5 Mandate and ISO 22398 Principles
Clause 8.5 requires organizations to test and exercise their business continuity procedures to ensure they are consistent with their business continuity objectives. The standard requires that exercises and tests must:
- Be consistent with the scope and objectives of the BCMS;
- Be based on plausible scenarios with clearly defined aims and objectives;
- Validate business continuity strategies, solutions, and plans over time;
- Minimize the risk of disruption to operations during conduct;
- Produce documented post-exercise reports, evaluations, and recommendations;
- Drive continual improvement through timely corrective action plans (CAPs);
- Be reviewed and updated at planned intervals and in response to significant organizational or contextual changes.
The Critical Distinction: Exercising vs. Testing
While Clause 8.5 couples "exercising and testing" into a single requirement, the Lead Implementer must understand the precise technical and operational distinction between these two complementary activities:
| Attribute | Exercising (People & Decision-Making) | Testing (Technology, Assets & Infrastructure) |
|---|---|---|
| Primary Focus | Human competence, teamwork, communication paths, leadership decision-making, and plan usability. | Technical pass/fail performance, equipment functionality, data integrity, and automated failover mechanics. |
| Primary Question | "Can our people execute the procedures effectively and coordinate decisions under simulated stress?" | "Does the technical solution, secondary power generator, or database replication script work as engineered?" |
| Measurement Baseline | Qualitative and quantitative: Decision timeliness, role clarity, situational awareness, and handover effectiveness. | Binary or quantitative: Pass/fail, data loss delta (actual vs. RPO), and failover execution duration (actual vs. RTO). |
| Typical Scope | Incident Management Teams (IMT), Crisis Management Teams (CMT), business process owners, and external liaison cells. | Data centers, telecommunications links, backup generators, fire suppression systems, and call center telephony routing. |
| Failure Implication | Uncovers training deficits, ambiguous plan wording, command bottlenecks, or unrealistic assumptions. | Uncovers hardware defects, software misconfigurations, network latency bottlenecks, or script execution bugs. |
[!IMPORTANT] Comprehensive Validation Requires Both A successful Disaster Recovery (DR) test confirming that virtual machines spin up at a secondary data center within 45 minutes does not prove business continuity. Business continuity is only validated when the human workforce successfully accesses those systems, executes manual workarounds during the transition, processes transactions at or above the Minimum Business Continuity Objective (MBCO), and delivers products or services to customers.
2. Purpose and Strategic Benefits of an Exercise Programme
An exercise programme is not a one-off annual event designed to appease certification auditors; it is an ongoing, systematic capability development framework. An effective exercise programme delivers six strategic benefits:
┌─────────────────────────────────────────┐
│ Strategic Benefits of Clause 8.5 │
│ Exercise Programme │
└────────────────────┬────────────────────┘
│
┌───────────────────┬─────────────────┼───────────────────┬───────────────────┐
▼ ▼ ▼ ▼ ▼
┌──────────────┐ ┌──────────────┐ ┌──────────────┐ ┌──────────────┐ ┌──────────────┐
│ Plan │ │ Personnel │ │ Gap & Single │ │ Metrics & │ │ Stakeholder │
│ Validation │ │ Competence │ │ Point-of- │ │ Capability │ │ & Regulatory │
│ & Usability │ │ & Muscle │ │ Failure │ │ Verification │ │ Confidence │
│ Verification │ │ Memory │ │ Discovery │ │ (RTO/RPO) │ │ (Compliance) │
└──────────────┘ └──────────────┘ └──────────────┘ └──────────────┘ └──────────────┘
- Validating Business Continuity Plans (BCPs) and Procedures: Exercises expose outdated contact directories, incorrect operational assumptions, unworkable manual workarounds, and gaps in standard operating procedures (SOPs).
- Developing Personnel Competence and Muscle Memory: Under Clause 7.2 (Competence), personnel with designated continuity roles must be trained. Exercises transform theoretical classroom knowledge into instinctive operational capability under simulated time pressure.
- Identifying Unforeseen Gaps and Dependencies: Exercises systematically uncover hidden single points of failure (SPOFs), missing equipment, undocumented upstream supplier dependencies, and software license constraints.
- Verifying Performance Against Recovery Targets (RTO, RPO, MBCO): Exercises provide the empirical data required to determine whether stated Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) are technically and operationally achievable.
- Enhancing Inter-Agency and Cross-Functional Coordination: Exercising builds trust and communication pathways between disparate functional units—such as IT, Legal, Human Resources, Facilities, Operations, and Corporate Communications—as well as external emergency responders and key suppliers.
- Satisfying Regulatory and Contractual Compliance: Fulfilling mandatory requirements set by financial regulators, data protection authorities, critical infrastructure directives, and customer service level agreements (SLAs).
3. Designing a Multi-Year Progressive Exercise Programme
ISO 22398 and ISO 22301 emphasize that an organization should not attempt complex, high-risk exercises immediately. Instead, Lead Implementers must construct a Multi-Year Exercise Programme (typically 3 to 5 years) that employs the "Crawl, Walk, Run" progressive complexity model.
The Progressive Exercise Maturity Model
Exercise
Complexity
▲
│ ┌──────────────────────────────┐
│ │ STAGE 4: LIVE SIMULATIONS │
│ │ • Full-Scale Live Cutover │
│ │ • Multi-Site Relocation │
│ ┌──────────────────────┤ • Unannounced Complex Scen. │
│ │ STAGE 3: FUNCTIONAL │ • External Entity Integr. │
│ │ • Operations Center │└──────────────────────────────┘
│ │ • Real-Time Injects │
│ ┌────────────────────────────┤ • Time Compression │
│ │ STAGE 1: DISCUSSION-BASED │ • Tactical Hand-offs│
│ │ • Orientation Seminars │└─────────────────────┘
│ │ • Tabletop Exercises (TTX)│
│ │ • Policy & Role Walkthrs │
│ └────────────────────────────┘
│
└────────────────────────────────────────────────────────────────────────────────────────►
Year 1 Year 2 - 3 Year 4 - 5 Time
Multi-Year Programme Progression Matrix
| Programme Phase | Exercise Type | Primary Focus | Target Audience | Key Objectives |
|---|---|---|---|---|
| Year 1: Foundation ("Crawl") | Seminars, Workshops & Tabletop Exercises (TTX) | Plan familiarization, role validation, and command structure clarification. | Crisis Management Team (CMT), Business Unit Leads, Plan Authors. | • Confirm understanding of BC policy and roles.<br/>• Validate notification procedures and call trees.<br/>• Identify initial documentation gaps. |
| Year 2: Operationalization ("Walk") | Drills, Component Tests & Tactical Tabletops | Tactical execution of specific recovery procedures and technical failovers. | IT Recovery Teams, Emergency Response Teams (ERT), Specific Departments. | • Validate component failover (generator, UPS, secondary ISP).<br/>• Execute departmental manual workaround procedures.<br/>• Measure component RTO/RPO under controlled conditions. |
| Year 3: Integration ("Run") | Functional Exercises & Partial Live Failover | Multi-team coordination, high-tempo inject management, and time-pressured decision-making. | Combined CMT, IMT, IT DR teams, key business units, and select suppliers. | • Stress-test command and control under time compression.<br/>• Validate communication flow between tactical and strategic teams.<br/>• Test simultaneous loss of facilities and primary systems. |
| Year 4–5: Enterprise Resilience ("Fly") | Full-Scale Live Simulations & Unannounced Exercises | End-to-end operational resilience, live datacenter cutover, alternate site relocation, and third-party integration. | Enterprise-wide, executive leadership, external first responders, cloud providers, critical vendors. | • Execute live traffic cutover to secondary data center.<br/>• Relocate core staff to alternate recovery facilities.<br/>• Test unannounced response to complex, multi-vector disruptions. |
4. Formulating SMART Exercise Objectives
An exercise without clearly defined, measurable objectives is an expensive waste of organizational resources. Objectives define the exact criteria against which performance will be evaluated. In accordance with ISO 22398, all exercise objectives must adhere to the SMART framework:
- Specific: Clearly identify the exact capability, plan, team, system, or procedure being evaluated.
- Measurable: Establish quantitative or definitive qualitative thresholds (e.g., elapsed time, percentage of notifications acknowledged, volume of transactions processed).
- Achievable: Calibrated to the organization's current maturity level and technical architecture without setting participants up for guaranteed failure.
- Relevant: Directly aligned with the organization's Business Impact Analysis (BIA), Prioritized Activities, RTO, RPO, and MBCO targets.
- Time-bound: Bound by specific temporal constraints (e.g., within 2 hours of exercise declaration, within the designated 4-hour exercise window).
Non-Compliant vs. SMART Exercise Objectives
| Poor / Non-Compliant Objective (Audit Finding) | Compliant SMART Objective (ISO 22301 Aligned) | Exam Analysis & Justification |
|---|---|---|
| "Test the IT disaster recovery plan to see if systems come back online." | "Validate that the core Oracle ERP database successfully fails over to the secondary AWS region with an RPO of $\le 15\text{ minutes}$ and an RTO of $\le 60\text{ minutes}$ from the time of simulated primary region failure." | Specific to the ERP database; measurable via RPO/RTO metrics; achievable; relevant to prioritized activities; time-bound by strict duration. |
| "Exercise the Crisis Management Team on ransomware communication." | "Demonstrate the Crisis Management Team's ability to convene within 30 minutes of notification, draft initial stakeholder holding statements within 45 minutes, and issue regulatory notifications compliant with GDPR Article 33 within the 4-hour exercise window." | Defines exact convening times, specific deliverable milestones (holding statements, regulatory filings), and clear temporal boundaries. |
| "Check if staff can work from home if the office is closed." | "Verify that at least 85% of Customer Support personnel successfully authenticate to the Virtual Desktop Infrastructure (VDI) and achieve an inbound call handling capacity of $\ge 70%$ (MBCO) within 2 hours of workplace denial notification." | Quantifies participant percentage (85%), system target (VDI), performance capacity ($70%$ MBCO), and strict resumption timeline (2 hours). |
5. Exercise Governance, Oversight and Resource Allocation
Establishing and maintaining an exercise programme requires rigorous governance and executive oversight. Without formal governance, exercise schedules are frequently postponed or canceled due to competing operational priorities.
Governance Structure and Roles
┌────────────────────────────────────────┐
│ BCMS Steering Committee │
│ • Executive Sponsorship & Budget │
│ • Multi-Year Programme Approval │
│ • Corrective Action Plan Oversight │
└───────────────────┬────────────────────┘
│
▼
┌────────────────────────────────────────┐
│ Exercise Planning Team │
│ • Exercise Programme Manager │
│ • Lead Scenario Designer │
│ • Technical & Logistics Coordinators │
└───────────────────┬────────────────────┘
│
┌───────────────────┴────────────────────┐
▼ ▼
┌──────────────────────────────┐ ┌──────────────────────────────┐
│ Exercise Control Cell │ │ Evaluation & Safety Team │
│ • Exercise Director │ │ • Lead Evaluator │
│ • Controllers / Facilitators│ │ • Functional Evaluators │
│ • Simulation Cell (SIMCELL) │ │ • Exercise Safety Officer │
└──────────────────────────────┘ └──────────────────────────────┘
Steering Committee & Management Responsibilities (Clause 5.1 & 8.5)
- Approving the Multi-Year Exercise Plan: Formal sign-off on exercise dates, operational scopes, and scenarios.
- Allocating Necessary Resources: Authorizing operational budgets for external simulators, testing tools, backup infrastructure usage, and staff overtime.
- Ensuring Cross-Departmental Participation: Mandating attendance across business lines and preventing operational managers from "opting out" of exercises.
- Enforcing Accountability for Corrective Actions: Reviewing post-exercise After-Action Reports (AARs) and holding action owners accountable for closing identified gaps.
6. Scenario Design: Plausible, Challenging and Unannounced Exercises
Clause 8.5 mandates that exercises must be based on plausible scenarios. A scenario describes the simulated sequence of disruptive events that creates the operational conditions required to evaluate specific continuity arrangements.
The Consequence-Based Approach to Scenario Design
In alignment with ISO 22301 philosophy, scenarios should focus on the loss of critical resource categories rather than becoming overly fixated on the specific geopolitical, criminal, or environmental trigger:
- Loss of Facilities / Workplace Denial: Physical inaccessibility of primary buildings (e.g., structural fire, localized contamination, cordon due to civil unrest, extended power outage).
- Loss of Technology / Data / Telecommunications: Complete failure of primary data centers, cloud infrastructure outage, cryptographic ransomware encryption, fiber optic line severance, or enterprise software corruption.
- Loss of People / Workforce Absenteeism: Sudden unavailability of key personnel or critical mass of staff (e.g., pandemic outbreak, transportation strike, localized food poisoning incident).
- Loss of Critical Third-Party Suppliers / Dependencies: Upstream supply chain insolvency, failure of a single-source SaaS provider, logistics hub collapse, or national utility grid failure.
Compound Scenarios
To challenge mature organizations, Lead Implementers should design compound scenarios—simultaneous or cascading disruptions that test organizational resilience under compound stress (e.g., a catastrophic hurricane that causes widespread power outages while simultaneously triggering a targeted ransomware attack on backup systems).
Unannounced Exercises: Strategic Value, Risks and Prerequisites
An unannounced exercise is conducted without prior notification to the responding participants. While highly effective at testing true operational readiness and alerting speed, unannounced exercises introduce severe operational risks if mismanaged.
| Aspect | Unannounced Exercise Advantages | Unannounced Exercise Risks & Hazards |
|---|---|---|
| Operational Reality | Measures true baseline response speed, genuine alert acknowledgment, and unprompted plan usage. | Can induce genuine panic, accidental emergency service calls (911/999/112), or real-world reputational leaks. |
| Absence of Pre-Staging | Prevents teams from "studying for the test," pre-configuring systems, or altering shift staffing to guarantee success. | May cause accidental shutdown of live production databases or unintended triggering of disaster recovery failover mechanisms. |
| Staff Dependency Testing | Validates whether deputies and secondary personnel can step up when primary managers are unavailable. | Can disrupt critical daily business operations, client deliverable deadlines, or high-value financial settlements. |
[!CAUTION] Mandatory Prerequisites for Unannounced Exercises
- High BCMS Maturity: Never conduct unannounced exercises in Year 1 or before all plans have been validated through announced tabletops and functional drills.
- Executive Pre-Authorization: Explicit, written approval from the Chief Executive Officer and Legal Counsel.
- Trusted Shadow Observers: Senior controllers embedded at key physical sites with direct communications to the Exercise Director to immediately intervene if safety boundaries are approached.
- Pre-Notified External Authorities: Prior notification to local law enforcement, fire services, building security, and key cloud vendors to prevent false alarm responses.
7. Safety, Containment and Operational Risk Management
Clause 8.5 explicitly requires that the organization shall conduct exercises in a manner that minimizes the risk of disruption to operations. An exercise must never cause an actual disaster.
The "Do No Harm" Governance Framework
┌─────────────────────────────────────────────────────────────────────────┐
│ EXERCISE SAFETY & CONTAINMENT RULES │
├─────────────────────────────────────────────────────────────────────────┤
│ 1. Production Data Isolation: Never use unencrypted live customer data │
│ in uncontained testing environments. │
│ 2. Communication Watermarking: Prefix all messages with 'EXERCISE ONLY'.│
│ 3. Designated Safety Officer: Independent officer with immediate abort │
│ authority across all operational venues. │
│ 4. Universal Abort Code Word: Immediate cessation upon broadcast of │
│ 'NO PLAY' or 'CODE RED - REAL WORLD EMERGENCY'. │
│ 5. Isolated Telephony & Routing: Use dedicated test SIMs/inboxes to │
│ prevent external public or customer leakage. │
└─────────────────────────────────────────────────────────────────────────┘
Key Safety Safeguards
- The Exercise Safety Officer (ESO): An independent safety professional appointed to monitor all physical, operational, and psychological safety aspects during exercise execution. The ESO has absolute, unilateral authority to freeze or abort the exercise immediately without seeking management approval.
- Standardized Communication Watermarking: Every verbal transmission, radio call, SMS alert, simulated press release, email, and instant message must begin and conclude with the clear phrase:
"EXERCISE - EXERCISE - EXERCISE"or"THIS IS A TEST EXERCISE ONLY". - Universal Real-World Abort Code Words: The exercise planning documentation must define unambiguous code words (e.g.,
"NO PLAY"or"CODE RED REAL-WORLD"). When spoken or broadcast, all exercise activities instantly cease, participants drop out of simulation mode, and real-world safety procedures take immediate precedence. - Production System Safeguards: When testing technical failover, strict firewall boundaries and isolated network subnets must be established to prevent test scripts from corrupting live production databases, issuing false trading orders, or terminating active client connections.
8. Worked Implementation Scenario: FinTech Multi-Year Programme & Safety Interruption
Context
NexPay Global, an international payment settlement platform processing $250M daily, is building its exercise programme under ISO 22301 Clause 8.5.
Multi-Year Programme Schedule
- Year 1: Tabletop exercises for the Executive Crisis Management Team validating ransomware response protocols and regulatory notification workflows.
- Year 2: Functional component drills testing automated database failover to secondary cloud zones and call center remote-work activation.
- Year 3: Multi-vector unannounced functional exercise combining simulated fiber-cut, primary data center power loss, and partial executive unavailability.
Safety Incident & Abort Protocol Execution
During the Year 3 functional exercise, the simulated scenario required the Lead Systems Engineer to execute a secondary gateway routing script. In the high-stress, time-compressed environment:
- Error: The engineer mistakenly opened a terminal connected to the live production settlement gateway instead of the designated staging environment and initiated a route modification.
- Detection: The embedded Exercise Controller observing the engineer noticed the production host IP address and immediately shouted the abort code:
"NO PLAY! NO PLAY! THIS IS A REAL-WORLD EMERGENCY STOP!" - Immediate Action: The exercise was instantly frozen enterprise-wide. The Controller and Engineer verified that no production packets had been dropped, rolled back the pending shell command, and notified the Exercise Director.
- Outcome: The Exercise Director logged the near-miss, ensured production integrity, and resumed the exercise 25 minutes later only after re-verifying terminal isolation safeguards.
9. PECB Exam Warning Traps & Implementation Pitfalls
[!CAUTION] Critical Exam Traps for Section 9.1
- Trap: "Exercising to Pass" vs. "Exercising to Learn": If an exercise concludes with zero findings, zero delays, and 100% flawless execution, it is an audit red flag indicating a poorly designed, non-challenging exercise. The primary purpose of Clause 8.5 is to discover unknown vulnerabilities in a safe environment before a real disaster strikes.
- Trap: Confusing Scope with Objectives: Exercise scope defines the operational boundaries (which locations, departments, systems are included or excluded). Exercise objectives define the specific measurable criteria used to judge whether the response succeeded.
- Trap: Running Unannounced Exercises Without Safety Controls: Exam questions often propose conducting an unannounced full-scale exercise in Year 1 of a BCMS without senior executive sign-off. This represents a severe nonconformity and operational hazard.
- Trap: Failing to Separate Planners from Players: If the person who wrote the scenario and injects also acts as a primary player responding to the incident, the exercise validity is completely compromised due to insider bias.
An organization implementing ISO 22301:2019 is establishing its multi-year exercise programme. The BCMS Manager suggests conducting an unannounced full-scale live data center cutover exercise during the first month following initial plan documentation. How should the Lead Implementer advise the Steering Committee?
Which of the following statements correctly distinguishes between 'exercising' and 'testing' within the context of ISO 22301:2019 Clause 8.5?
During a high-stress functional business continuity exercise, a participant operating in the simulation room collapses due to a medical emergency. What is the immediate procedural requirement according to exercise risk management principles?