Cybersecurity GRC 14 items
Breach & Attack Simulation / Purple-Team Exercise
Evaluates a breach-and-attack-simulation and purple-team program covering scoping, adversary emulation, detection validation, collaboration, and remediation.
MITRE ATT&CKNIST 800-53CIS
Free PDF · enter your email to download.
Scoping & Planning
- Are exercise objectives and success criteria defined with stakeholder agreement? *
- Are the threat scenarios based on relevant adversary TTPs and threat intelligence? *
- Are rules of engagement, scope boundaries, and safety controls documented and approved? *
- Is the target environment (production vs. staging) and blast radius agreed in advance? *
Execution
- Are simulations mapped to specific MITRE ATT&CK techniques across the kill chain? *
- For purple-team exercises, do red and blue teams collaborate in real time? *
- Is safe, non-destructive tooling used with continuous monitoring for adverse impact? *
- Are both preventive and detective controls exercised (not just endpoint)?
Validation & Measurement
- Is prevention/detection efficacy measured per technique (blocked, alerted, missed)? *
- Is detection coverage tracked as a percentage of tested techniques?
- Are detection and response times (MTTD/MTTR) captured during the exercise?
Remediation & Continuous Improvement
- Are gaps documented with owners and remediation timelines? *
- Are new or tuned detections created for missed techniques? *
- Are exercises run on a recurring cadence to measure improvement over time?
Download the full Breach & Attack Simulation / Purple-Team Exercise checklist
Get it as a clean, printable PDF — free.
