Quarterly review and tabletop exercise
A half-day review each quarter.
Before you start
Bring the last quarter’s capacity graphs, the hardware asset register, the incident tickets closed since the previous review, and an export of admin accounts with their roles and TFA state. The tabletop needs a scenario chosen in advance and the people who would actually be paged in the room; picking one on the day produces a discussion rather than an exercise.
Order of work
The items run in four phases and the frontmatter list is in that order.
capacity-review and hardware-inventory are the inventory phase. They establish what
the platform currently is — how much of it is consumed, how fast that is moving, and how
much warranty is left on the parts holding it up. Both feed procurement, which is why
they come before anything that might commit money.
hardening-review and access-review are the security phase, read as a pair: one asks
whether the configuration still answers the current threat picture, the other asks who
can reach it. penetration-test sits with them and is the only optional item on the
list; schedule it when a change since the last review warrants outside eyes.
runbook-review, dr-tabletop and backup-restore-test are the readiness phase and
the core of the quarter. The order matters: read the runbooks against what actually
happened, exercise them on paper against a scenario, then prove the one assumption a
tabletop cannot test by restoring real data from the off-site copy.
subscription-renewal closes the review. It is last because it is administrative, and
first to be forgotten in a quarter where something else went wrong.
Output
Every item ends as a check or a finding with an owner and a date. The restore drill is the one item that cannot be signed off on judgement: either data came back from off-site and was verified, or the item is unchecked and the quarter has an open risk.