# AEGIS — Tabletop Exercise Framework - **Document ID:** ARCH-49 - **Phase:** E.3 — Adversarial/Defensive Teams - **Status:** Draft for review (post four-reviewer discipline) - **Version:** 0.1 - **Date:** 2026-07-10 - **Owner:** Chief Security Architect --- ## 1. Purpose Codify structured, scenario-driven walkthroughs across engineering, ops, security, comms, legal, and executive stakeholders. Tabletops build cross-team decision-making muscle memory without production risk. ## 2. Scope Tabletops complement — do not replace — live drills. They target situations where live rehearsal is impractical: - Cross-team incident coordination. - Executive decision paths (public disclosure, regulator engagement). - Legal escalations. - Multi-region operational coordination. - Reputation-affecting incidents. - Post-mortem culture drills. ## 3. Cadence - **Biannually** cross-team SEV-1 scenarios. - **Quarterly** narrow scenarios per functional team. - **On demand** after major incident post-mortem or new subsystem readiness. ## 4. Format - Scenario prepared by IR lead + Auditor observer. - Structured 90-min session; decisions logged. - Retrospective produces action items with owners + due dates. - Actions integrated into runbooks (ARCH-21) + governance improvements. ## 5. Roles - **Facilitator** (rotating; PA or dedicated IR lead). - **Scribe** (records decisions + rationale). - **Auditor observer**. - **Participants** — actual on-call + IC + Communicator + Legal + Executive where scenario warrants. - **Adversary role** — facilitator injects new information per script. ## 6. Assumption (hypothesis) - **H-1.** *Cross-team tabletops surface coordination gaps faster than incidents alone.* - Evidence: initial pilot; industry practice. - Validation: measure gap-to-fix time. - Confidence: Medium. - Expiration: annually. - Review Date: 12 months. ## 7. Trust Score Contribution Tabletop outcomes feed `Operational History`. ## 8. Independent Architecture Review - **F-1.** *Tabletops don't test tooling.* Complementary to live drills + chaos. - **F-2.** *Executive availability.* Scheduled in advance; brief prep. ## 9. Adversarial Architect Review - **A-1.** *Scenarios softened to spare feelings.* Facilitator rotation; Auditor. - **A-2.** *Insider learns tabletop-specific patterns to time attacks.* Scenarios drawn from a large library; parameterized. ## 10. Operational Reliability Review - **O-1.** Sustainable cadence. - **O-2.** Action-item close rate is a metric. ## 11. Self-Critique - **S-1.** *Tabletop is only as good as scenario quality.* Library rotation + external contribution. - **S-2.** *Executive engagement varies.* Governance-level buy-in + auditor visibility. ## 12. First-Target Analysis and Redesign **Target:** action-item follow-through. Tabletops produce actions that then quietly slip. Response: action items tracked as tickets with SLOs; overdue = SEV-3; auditor visibility. ## 13. Future Risks / Known Limitations / Out-of-Scope / Retirement - **Future Risks.** Remote-first orgs may lose tabletop energy — mitigate with structured facilitation. - **Known Limitations.** No tooling test. - **Out-of-Scope.** Executive-time-consuming full simulations — those live in game days. - **Retirement Conditions.** Never — tabletops permanent. ## 14. Decisions ### D-49-1. Biannual cross-team + quarterly narrow tabletops with tracked action items - **Reason.** Cross-team coordination muscle memory. ## 15. Change Log - **0.1 (2026-07-10)** — Initial draft.