# CP-03 Contingency Training

NIST SP 800-53 control. Family: CP Contingency Planning. Function: corrective. Baselines: low, moderate, high. Mapping licence: CC BY-SA 4.0.

Statement: a. Provide contingency training to system users consistent with assigned roles and responsibilities: 1. Within [Assignment: organization-defined time period] of assuming a contingency role or responsibility; 2. When required by system changes; and 3. [Assignment: organization-defined frequency] thereafter; and b. Review and update contingency training content [Assignment: organization-defined frequency] and following [Assignment: organization-defined events].
Guidance: Contingency training provided by organizations is linked to the assigned roles and responsibilities of organizational personnel to ensure that the appropriate content and level of detail is included in such training. For example, some individuals may only need to know when and where to report for duty during contingency operations and if normal duties are affected; system administrators may require additional training on how to establish systems at alternate processing and storage sites; and organizational officials may receive more specific training on how to conduct mission-essential functions in designated off-site locations and how to establish communications with other governmental entities for purposes of coordination on contingency-related activities. Training for contingency roles or responsibilities reflects the specific continuity requirements in the contingency plan. Events that may precipitate an update to contingency training content include, but are not limited to, contingency plan testing or an actual contingency (lessons learned), assessment or audit findings, security incidents or breaches, or changes in laws, executive orders, directives, regulations, policies, standards, and guidelines. At the discretion of the organization, participation in a contingency plan test or exercise, including lessons learned sessions subsequent to the test or exercise, may satisfy contingency plan training requirements.

## Enhancements (2)
- CP-03(01) Simulated Events. Baselines: high
- CP-03(02) Mechanisms Used in Training Environments
Each enhancement's statement: /api/v1/controls/CP-03?fields=enhancements

## Patterns that use it (4)
- Standard (4): SP-001 Client Module; SP-002 Server Module; SP-008 Public Web Server Pattern; SP-014 Awareness and Training Pattern

## Clauses by framework (46 frameworks)
- iso_27001_2022: A.5.29, A.6.3. OSA's own, not in NIST's crosswalk: A.5.29
- iso_27002_2022: 5.29
- cobit_2019: DSS04
- nis2: Art. 21(2)(c)
- mas_trm: 8
- bsi_grundschutz: DER.4
- anssi: Hygiene.4, Hygiene.35, SecNumCloud.18.2
- osfi_b13: B-13.2.6
- finma_circular: IV.E(92), IV.E(93)
- gdpr: Art.32(1)(d)
- dora: Art.11(6), Art.13(6)
- bio2: 5.29
- rbi_csf: ITGRCA.29
- fisc: FISC.O5
- hkma_tme1: TME1.6.1, TME1.6.3
- mlps_2: 8.1.10.11
- dnb_good_practice: DNB.11.2
- cbb_tm: TM-14
- cbuae: CR-13
- nca_ecc: 3-1
- qatar_nia: BC
- uae_ia: T12
- bog_cisd: CISD-BCM
- bom_ctrm: 5.2
- cbe_csf: OVM-2
- cbn_csf: Part3.7
- sa_js2: JS2-7.5
- bot_cyber: Ch4.2
- cpmi_pfmi: CG.RR, PFMI.P17
- eba_ict: 3.7.4
- ecb_croe: CROE.2.5.2
- hipaa_sr: §164.308(a)(7)(i), §164.308(a)(7)(ii)(D)
- nydfs_500: 500.16
- sebi_cscrf: BCP-DR, CCMP
- fca_sysc_13: SYSC 13.8.1
- hitrust_csf: 12.b, 12.c
- iso_27799: 17.1
- lloyds_ms: MS8.6, MS9.2
- naic_ds: 4F-b
- nhs_dspt: NDG-7.1
- solvency_ii: DR.266-BCP, EIOPA-ICT-4.10
- csa_ccm_v4: BCR-04, BCR-06
- csa_aicm: BCR-04, BCR-06
- mica: Art.62(6)
- basel_sco60: SCO60.53
- sec_custody_digital: SEC-CD-12
OSA's mapping for iso_27001_2022 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/CP-03
- Clauses only: /api/v1/controls/CP-03?fields=mappings
- Page for people: /controls/cp-03/
