ISO 27001 incident and continuity exercises
ISO/IEC 27001:2022 groups incident management into Annex A 5.24 to 5.28, with information security during disruption at 5.29 and ICT readiness for business continuity at 5.30. Of these, 5.30 is the one whose wording includes testing.
How an exercise supports each control
ISO 27001 at a glance
- Framework
- ISO/IEC 27001:2022
- References
- A.5.24 to A.5.30
- Where testing comes up
- Annex A 5.24 to 5.27 (incident management), 5.29, and 5.30 (ICT readiness is “tested”). Clause 10.2, corrective action. ISO 22301 clause 8.5 for a BCMS.
- Does the text require it?
- A.5.30 includes testing, unless excluded in your Statement of Applicability with justification.
- How often
- Not fixed. ISO 22301: planned intervals.
Note: Calmdrill is designed to support your evidence. Your certification body decides whether it is sufficient.
| Control | What a Calmdrill exercise gives you |
|---|---|
| A.5.24 Planning and preparation | Evidence that roles and processes exist, and that people know them under pressure |
| A.5.25 Assessment and decision | A timestamped record of triage and severity decisions |
| A.5.26 Response | A record of the response against your documented procedure |
| A.5.27 Learning from incidents | Lessons learned and owned improvement actions |
| A.5.29 Security during disruption | Scenarios such as CD-01 test whether security holds when you are under pressure, for example the temptation to switch off mTLS |
| A.5.30 ICT readiness for business continuity | Discussion-based testing of continuity decisions (CD-03, CD-04, CD-11). Pair it with technical recovery tests. |
| Clause 10.2 Corrective action | An improvement tracker with owners, due dates and closure |
Corrective action you can show
Clause 10.2 wants corrective action, with documented information as the evidence. Every action leaves a drill with an owner, a due date and a success measure. The tracker records when it closed.
| No. | Action | Owner | Due | Success measure | Status | Closed |
|---|---|---|---|---|---|---|
| 4 | Status page templates for partial login outages, with "what's affected" and "what you can do" wording and a 30-minute update reminder | Jo | 16 Oct 2026 | In the next drill, the first update includes impact and workaround within 15 minutes | Open | |
| 5 | Certificate and expiry inventory: intermediate CA, Apple push certificate, Okta SAML certificate, domain renewals, each with owner and expiry date | Platform with Security | 23 Oct 2026 | Every item has a named owner and alerts to more than one person | Open | |
| 6 | Automate intermediate CA rotation and write a re-issue runbook | Platform | 6 Nov 2026 | Rotation tested in staging and the runbook reviewed by a second engineer | Open |
Continuity: A.5.30 and ISO 22301
If you are also working towards ISO 22301, clause 8.5 expects an exercise programme at planned intervals, with post-exercise reviews. The Pro edition’s Annual Drill Programme is built for exactly that.
| Scenario | The continuity decision it tests |
|---|---|
| CD-03 Region Grey | Evacuating an Availability Zone or failing over to another region, with RPO and RTO made explicit |
| CD-04 The Restore That Wasn’t | Swapping, restore-and-merge, application-level repair or read-only mode after silent data loss |
| CD-11 Nobody Home | Running an incident when the identity provider is down, and whether break-glass arrangements actually work |
Note: A tabletop tests decisions. It restores nothing, so for A.5.30 keep your technical recovery-test records alongside the exercise report.
Start with one drill
The Kit has all twelve scenarios, the Game Master and the evidence templates: exercise plan, attendance record, report and tracker. $149 once, for your whole organisation.
Load the Game Master into a Claude or ChatGPT project, choose a scenario and tell it the exercise is for ISO 27001. It notes that in the report header, and the report’s evidence section cites the scenario’s Annex A references in careful wording.