{"data":{"id":"CP-04","name":"Contingency Plan Testing","family":"CP","family_name":"Contingency Planning","withdrawn":false,"description":"a. Test the contingency plan for the system [Assignment: organization-defined frequency] using the following tests to determine the effectiveness of the plan and the readiness to execute the plan: [Assignment: organization-defined tests].\nb. Review the contingency plan test results; and\nc. Initiate corrective actions, if needed.","supplemental_guidance":"Methods for testing contingency plans to determine the effectiveness of the plans and identify potential weaknesses include checklists, walk-through and tabletop exercises, simulations (parallel or full interrupt), and comprehensive exercises. Organizations conduct testing based on the requirements in contingency plans and include a determination of the effects on organizational operations, assets, and individuals due to contingency operations. Organizations have flexibility and discretion in the breadth, depth, and timelines of corrective actions.","enhancements":[{"id":"CP-04(01)","name":"Coordinate with Related Plans","statement":"Coordinate contingency plan testing with organizational elements responsible for related plans.","baselines":["moderate","high"]},{"id":"CP-04(02)","name":"Alternate Processing Site","statement":"Test the contingency plan at the alternate processing site:\na. To familiarize contingency personnel with the facility and available resources; and\nb. To evaluate the capabilities of the alternate processing site to support contingency operations.","baselines":["high"]},{"id":"CP-04(03)","name":"Automated Testing","statement":"Test the contingency plan using [Assignment: organization-defined automated mechanisms].","baselines":[]},{"id":"CP-04(04)","name":"Full Recovery and Reconstitution","statement":"Include a full recovery and reconstitution of the system to a known state as part of contingency plan testing.","baselines":[]},{"id":"CP-04(05)","name":"Self-challenge","statement":"Employ [Assignment: organization-defined mechanisms] to [Assignment: organization-defined system or system component] to disrupt and adversely affect the system or system component.","baselines":[]}],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"nist_800_53":{"rev5":{"id":"CP-04","name":"Contingency Plan Testing","description":"a. Test the contingency plan for the system [Assignment: organization-defined frequency] using the following tests to determine the effectiveness of the plan and the readiness to execute the plan: [Assignment: organization-defined tests].\nb. Review the contingency plan test results; and\nc. Initiate corrective actions, if needed.","discussion":"Methods for testing contingency plans to determine the effectiveness of the plans and identify potential weaknesses include checklists, walk-through and tabletop exercises, simulations (parallel or full interrupt), and comprehensive exercises. Organizations conduct testing based on the requirements in contingency plans and include a determination of the effects on organizational operations, assets, and individuals due to contingency operations. Organizations have flexibility and discretion in the breadth, depth, and timelines of corrective actions.","related_controls":["AT-03","CP-02","CP-03","CP-08","CP-09","IR-03","IR-04","PL-02","PM-14","SR-02"],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"baseline_privacy":false,"new_in_rev5":false,"changes_from_rev4":""}},"compliance_mappings":{"iso_27001_2022":["A.5.29","A.5.30"],"iso_27002_2022":["5.29","5.30"],"cobit_2019":["DSS04"],"pci_dss_v4":[],"nist_csf_2":["ID.IM-02","ID.IM-04","RC.RP-03"],"cis_controls_v8":["CIS 11.5"],"soc2_tsc":["A1.3","CC7.4-POF10","CC7.5"],"finos_ccc":[],"iso_42001_2023":[],"iec_62443":[],"asd_e8":[],"nis2":["Art. 21(2)(c)"],"apra_cps_234":[],"mas_trm":["8"],"pra_op_resilience":["SS1/21-6.1","SS1/21-6.2","SS2/21-10.1"],"bsi_grundschutz":["DER.4"],"anssi":["Hygiene.35","SecNumCloud.18.2"],"osfi_b13":["B-13.2.6","B-13.3.5"],"finma_circular":["IV.E(94)","IV.E(95)","IV.E(96)","IV.F(97)"],"gdpr":["Art.32(1)(d)"],"dora":["Art.11(6)","Art.11(7)"],"bio2":["5.29","5.30"],"rbi_csf":["ITGRCA.29"],"fisc":["FISC.O5"],"lgpd_bcb":[],"hkma_tme1":["TME1.6.3"],"mlps_2":["8.1.10.9","8.1.10.11"],"dnb_good_practice":["DNB.11.2"],"cra":[],"swift_cscf":["SWIFT.7.4A"],"cbb_tm":["TM-14"],"cbuae":["CR-13"],"nca_ecc":["3-1","3-2"],"qatar_nia":["BC"],"uae_ia":["T12"],"bog_cisd":["CISD-BCM","CISD-X"],"bom_ctrm":["5.2"],"cbe_csf":["OVM-2"],"cbn_csf":["Part3.6","Part3.7","Part3.8"],"sa_js2":["JS2-7.5"],"bot_cyber":["Ch4.2"],"cpmi_pfmi":["CG.RR","CG.TE","PFMI.P17"],"eba_ict":["3.7.4"],"ecb_croe":["CROE.2.5.2","CROE.2.6.1"],"hipaa_sr":["§164.308(a)(7)(i)","§164.308(a)(7)(ii)(D)"],"iosco_cyber":["LE-1","PFMI-17","RR-5","TEST-1","TEST-4","TEST-5"],"nydfs_500":["500.16"],"sebi_cscrf":["BCP-DR","CCMP","RC.IM","RC.RP"],"nerc_cip":["CIP-009-6"],"nrc_73_54":["RG5.71-B-CP"],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":["RESPONSE"],"api_1164":["Sec 11"],"awia":["Sec 2013(b)"],"iaea_nss":["Sec 8"],"pci_pts":[],"fips_140":[],"cbest":[],"tiber_eu":[],"pci_hsm":[],"common_criteria":[],"isae_3402":[],"fca_sysc_13":["SYSC 13.8.1","SYSC 13.8.2","SYSC 13.9.5"],"fda_21_cfr_11":[],"fda_cyber":[],"hitrust_csf":["12.b","12.c"],"iso_27799":["17.1"],"lloyds_ms":["CRM.3","MS8.6","MS9.2"],"naic_ds":["4F-b"],"nhs_dspt":["NDG-7.1","NDG-7.3"],"pra_ss1_23":["P5.4"],"solvency_ii":["DR.266-BCP","DR.274","EIOPA-ICT-4.10"],"owasp_masvs_v2":[],"csa_ccm_v4":["BCR-04","BCR-06","BCR-10"],"csa_aicm":["BCR-04","BCR-06","BCR-10"],"ccss_v9":["1.06.3"],"mica":["Art.62(6)","Art.68(5)"],"basel_sco60":["SCO60.23","SCO60.53"],"bssc":["GSP-06"],"sec_custody_digital":["SEC-CD-12","SEC-CD-13"],"dpdpa":[]},"attack_techniques":[],"metadata":{"last_reviewed":"2026-10-03","review_notes":"2026-10-03: iso_27001_2022 A.5.30 added from NIST's SP 800-53 Rev 5 to ISO/IEC 27001:2022 crosswalk (OLIR entry 155), which OSA's mapping now takes as its base. 2026-10-03: nist_csf_2 RC.RP-03 added from NIST's CSF 2.0 to SP 800-53 Rev 5.2.0 crosswalk (OLIR entry 186), which OSA's mapping now takes as its base.","mapping_status":"complete"},"function":"corrective","used_by_patterns":["SP-001","SP-002","SP-034"]}}