Exercises and Testing under ISO 18788

Introduction

Security operations cannot rely solely on policies, SOPs, or past incident responses. The true measure of preparedness is how effectively an organization can test its systems, people, and resources against realistic conditions.

Clause 9.1 of ISO 18788:2015 emphasizes the importance of exercises and testing as part of performance evaluation. Testing provides assurance that security operations are not only theoretically sound but also practically effective in supporting Strategic, Tactical, and Operational Objectives.

Why Exercises and Testing Are Important

  1. Validation of Plans and Controls - Demonstrates that policies, SOPs, and controls work in practice.
  2. Gap Identification - Highlights weaknesses in training, resources, communication, or procedures.
  3. Alignment with Objectives - Ensures performance supports organizational goals at all levels.
  4. Learning and Improvement - Provides real-world lessons that feed back into risk registers and corrective action plans.
  5. Stakeholder Assurance - Gives clients, regulators, and communities confidence that the company can manage risks effectively.

The Five Testing Methodologies

To ensure comprehensive assurance, ISO 18788-aligned testing should follow structured methodologies. Each type has a distinct role and increasing complexity:

1. Desk-Top Testing (Tabletop Exercises)

  • Definition: A structured discussion exercise where managers and supervisors review response plans in a classroom or meeting environment.
  • Purpose: Test decision-making, role clarity, and communication chains.
  • Alignment:
    • Strategic: Board/CEO review of crisis management policies.
    • Tactical: Divisional review of SOPs against recent incidents.
    • Operational: Guard supervisors validating escalation protocols.

2. Functional Testing

  • Definition: Limited-scope tests of individual systems, controls, or processes.
  • Purpose: Validate whether specific functions (e.g., CCTV, alarms, radio communication) operate as expected.
  • Alignment:
    • Based on incidents reported (e.g., prior CCTV downtime → retest after corrective actions).

3. Walk-Through Testing

  • Definition: Physical walkthroughs of processes or scenarios, often involving role-players.
  • Purpose: Assess whether personnel understand and can perform SOPs step-by-step.
  • Alignment:
    • Operational: Shift teams practicing incident escalation.
    • Tactical: Testing evacuation routes or access control responses.

4. Scenario Testing

  • Definition: Realistic, simulated scenarios based on identified risks and past incidents.
  • Purpose: Evaluate integrated responses across multiple functions.
  • Examples: Armed robbery response, protest escalation, or community grievance.
  • Alignment:
    • Strategic: Evaluating crisis decision-making under reputational pressure.
    • Tactical: Regional command centres coordinating multi-site responses.
    • Operational: Security teams executing incident containment on the ground.

5. Full-Scale Testing (Simulation/Field Exercises)

  • Definition: Live simulations with full deployment of people, systems, and equipment.
  • Purpose: Stress-test the entire SOMS under near-real conditions.
  • Examples: Emergency evacuation drill, hostile intrusion test, large-scale community unrest.
  • Alignment:
    • Validates that strategic plans, tactical resources, and operational responses work together seamlessly.

Linking Testing to Objectives and Incidents

  • Strategic Level: Exercises must validate that the SOMS supports organizational goals (e.g., compliance, human rights, resilience).
  • Tactical Level: Testing evaluates whether departmental SOPs and risk registers are effective in addressing recurring incidents.
  • Operational Level: Frontline personnel practice real responses, ensuring they can meet daily objectives.

👉 Importantly: Incidents reported in the IMS must guide future testing scenarios. For example, if armed robberies or OHS accidents occur repeatedly, these risks must be tested through walk-throughs, scenario drills, or full-scale exercises.

Documentation and Audit Evidence

Auditors will expect:

  • Exercise and Testing Plans: Including objectives, scope, methodology, and roles.
  • Records of Execution: Logs, attendance registers, video evidence.
  • After-Action Reports: Findings, lessons learned, and corrective actions.
  • Improvement Logs: Evidence of how testing outcomes updated SOPs, risk registers, and training.
  • Management Review Minutes: Showing leadership evaluation of testing results.

Most reliable evidence: Recorded scenario drills, full-scale exercise reports.
Moderate: Tabletop attendance and feedback notes.
Least reliable: Verbal confirmation without records.

Conclusion

Exercises and testing are essential for operational readiness and continual improvement. By applying all five testing methodologies—Desk-Top, Functional, Walk-Through, Scenario, and Full-Scale—organizations ensure that their SOMS is validated, stress-tested, and aligned with Strategic, Tactical, and Operational Objectives.

When driven by incident data and risk registers, testing becomes a living assurance tool that closes the loop:

  • Incidents → Risks → Objectives → Exercises → Lessons → Improvement.

This cycle ensures ISO 18788-certified organizations are not just compliant, but also resilient, trustworthy, and adaptive in real-world conditions.