simpl.
Cybersecurity GRC 14 items

Breach & Attack Simulation / Purple-Team Exercise

Evaluates a breach-and-attack-simulation and purple-team program covering scoping, adversary emulation, detection validation, collaboration, and remediation.

MITRE ATT&CKNIST 800-53CIS

Free PDF · enter your email to download.

Scoping & Planning

  • Are exercise objectives and success criteria defined with stakeholder agreement? *
  • Are the threat scenarios based on relevant adversary TTPs and threat intelligence? *
  • Are rules of engagement, scope boundaries, and safety controls documented and approved? *
  • Is the target environment (production vs. staging) and blast radius agreed in advance? *

Execution

  • Are simulations mapped to specific MITRE ATT&CK techniques across the kill chain? *
  • For purple-team exercises, do red and blue teams collaborate in real time? *
  • Is safe, non-destructive tooling used with continuous monitoring for adverse impact? *
  • Are both preventive and detective controls exercised (not just endpoint)?

Validation & Measurement

  • Is prevention/detection efficacy measured per technique (blocked, alerted, missed)? *
  • Is detection coverage tracked as a percentage of tested techniques?
  • Are detection and response times (MTTD/MTTR) captured during the exercise?

Remediation & Continuous Improvement

  • Are gaps documented with owners and remediation timelines? *
  • Are new or tuned detections created for missed techniques? *
  • Are exercises run on a recurring cadence to measure improvement over time?

Download the full Breach & Attack Simulation / Purple-Team Exercise checklist

Get it as a clean, printable PDF — free.