Overview
ISO 22398:2013 - Societal security - Guidelines for exercises provides practical guidance for organizations to plan, conduct and improve exercise programmes and exercise projects. Applicable to all organization types (public or private), it helps build and mature capabilities by testing plans, people, procedures, equipment and inter‑organizational arrangements. The standard describes a generic approach covering programme-level planning, project design, conduct, evaluation and continual improvement.
Key Topics
- Exercise programme design: Establishing programme need, objectives, scope, resources, schedule and governance (including assignment of an exercise programme manager).
- Exercise project planning: Defining aims and objectives, target groups, scope, scenario development, scripts, injects and safety arrangements.
- Conducting exercises: Roles and responsibilities (exercise coordinator, observers, participants), run‑throughs, start‑up briefings, launch and termination procedures.
- Evaluation and improvement: Observation, debriefing, after‑action reports, evaluation against criteria, management review and corrective action to enable continual improvement.
- Terminology and definitions: Clear definitions for exercise, drill, test, scenario, inject, after‑action report, competence, risk and related terms (normative reference: ISO 22300).
- Supporting material: Informative annexes (e.g., needs analysis, national strategic exercises, scenario creation and exercise enhancement) to help tailor exercises to organizational needs.
Applications
ISO 22398 is designed for practical use across a wide range of exercise types and objectives:
- Validation and testing of emergency plans, business continuity and ICT disaster recovery systems.
- Training and competence development for leadership and operational staff through learning‑focused exercises and drills.
- Inter‑agency cooperation and communication testing in multi‑stakeholder incidents.
- Capability assessment and risk‑based improvement by identifying gaps, resource shortfalls and opportunities for corrective action.
- Experimental exercises to trial new procedures or technologies in a controlled environment.
Who should use this standard?
- Senior leadership and management responsible for organizational resilience.
- Exercise programme managers, exercise coordinators and exercise project teams.
- Emergency planners, business continuity professionals, security and risk managers, training departments, and external partners involved in multi‑agency exercises.
Related standards
- ISO 22300 - Societal security: Terminology (normative reference used for consistent definitions).
ISO 22398:2013 helps organizations establish a structured, risk‑informed exercise lifecycle - from needs analysis and scenario design to evaluation and continual improvement - to strengthen preparedness and societal security.