Preparing for cyber crisis management exercises
Original version
http://dx.doi.org/10.1007/978-3-030-50439-7_19Abstract
In this paper the authors discuss how to create a preparation schedule for ex-ercises (PSE) to support EXCON-teams and instructors for full-scaled com-bined crisis management and cyber-exercises. The process to create the prep-aration schedule starts by performing vulnerability analysis to identify the most relevant and likely threats to the organization, before processing historical threats and attacks to further focus our simulation sce-nario development by planning and designing a socio-technical scenario. Moreover, a plan for simulation that are realistic and based on the organiza-tion’s maturity will be considered, and finally, in terms of a societal crisis impact exercise necessary lectures will be prepared. After this framework has been reviewed by the HCI International 2020, we plan to test the model when planning for exercises at the Norwegian Cyber Range (NCR) environment. NCR will be an arena where testing, training, and exercise will be used to expose individuals, public and private organiza-tions, government agencies to simulate socio-technical cyber security events and situations in a realistic but safe environment.