Organization must, as part of it's cyber risk management framework, maintain and review digital operational resilience testing program. It must help the organisation to asses their preparedness to:
- handle ICT-related incidents
- identify weaknesses, deficiencies and gaps in digital operational resilience
- implement corrective measures
The testing program:
- should include variety of assessments, tests and tools to ensure the correctness of the testing.
- should be done with a risk-based approach to recognize the evolving landscape of ICT-related risks.
- be conducted by independent parties, external or internal, by ensuring sufficient resources and avoid conflict of interests
The organization should have processes to prioritize, classify and remedy the issues uncovered by the testing program.
As part of the program the organisation must ensure yearly testing of all ICT systems and applications that support critical or important functions.