Skip to main content
U.S. flag

An official website of the United States government

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Maintaining Effective Information Technology (IT) Security Through Test, Training, and Exercise Programs

Published

Author(s)

Shirley M. Radack

Abstract

This bulletin summarizes the information provided in NIST SP 800-84, concerning the need to design, develop, conduct, and evaluate Test, Training, and Exercise (TT&E) activities. The bulletin provides information on how organizations can prepare for, respond to, manage, and recover from adverse events, which could disrupt operations and interfere with the conduct of the organization¿s business, by developing TT&E programs. Topics covered include TT&E actions that individual organizations can manage within their overall IT planning or within their emergency-handling capabilities for IT. Other topics covered include the role of training in a TT&E program and the relationship of training to exercises and tests.
Citation
ITL Bulletin -

Keywords

functional exercises, information security, information technology, planning, security policies, tabletop exercises, tests, training, TT&E

Citation

Radack, S. (2006), Maintaining Effective Information Technology (IT) Security Through Test, Training, and Exercise Programs, ITL Bulletin, National Institute of Standards and Technology, Gaithersburg, MD, [online], https://tsapps.nist.gov/publication/get_pdf.cfm?pub_id=50963 (Accessed April 29, 2024)
Created December 19, 2006, Updated January 27, 2020