← Controls / CP

CP-03 Contingency Training

Contingency Planning

Low Moderate High

Description

a. Provide contingency training to system users consistent with assigned roles and responsibilities: 1. Within [Assignment: organization-defined time period] of assuming a contingency role or responsibility; 2. When required by system changes; and 3. [Assignment: organization-defined frequency] thereafter; and b. Review and update contingency training content [Assignment: organization-defined frequency] and following [Assignment: organization-defined events].

Supplemental Guidance

Contingency training provided by organizations is linked to the assigned roles and responsibilities of organizational personnel to ensure that the appropriate content and level of detail is included in such training. For example, some individuals may only need to know when and where to report for duty during contingency operations and if normal duties are affected; system administrators may require additional training on how to establish systems at alternate processing and storage sites; and organizational officials may receive more specific training on how to conduct mission-essential functions in designated off-site locations and how to establish communications with other governmental entities for purposes of coordination on contingency-related activities. Training for contingency roles or responsibilities reflects the specific continuity requirements in the contingency plan. Events that may precipitate an update to contingency training content include, but are not limited to, contingency plan testing or an actual contingency (lessons learned), assessment or audit findings, security incidents or breaches, or changes in laws, executive orders, directives, regulations, policies, standards, and guidelines. At the discretion of the organization, participation in a contingency plan test or exercise, including lessons learned sessions subsequent to the test or exercise, may satisfy contingency plan training requirements.

Changes from Rev 4

Adds text to review and update contingency training content Adds parameters for frequency of review/update and following specified events Discussion includes events that may precipitate an update to contingency training content

Enhancements (2)

What NIST adds to this control. Select one to read its statement.

CP-03(01) Simulated Events High

Incorporate simulated events into contingency training to facilitate effective response by personnel in crisis situations.

CP-03(02) Mechanisms Used in Training Environments

Employ mechanisms used in operations to provide a more thorough and realistic contingency training environment.

Patterns that use this control (4)

Grouped by the emphasis each pattern gives it.

Compliance Mappings

ISO 27001:2022

A.5.29A.6.3

ISO 27002:2022

5.29

COBIT 2019

DSS04

CSA CCM v4

BCR-04BCR-06

CSA AICM v1

BCR-04BCR-06

NIS2 Directive

Art. 21(2)(c)

MAS TRM

8

BSI IT-Grundschutz

DER.4

ANSSI

Hygiene.4Hygiene.35SecNumCloud.18.2

FINMA Circular 2023/1

IV.E(92)IV.E(93)

OSFI B-13

B-13.2.6

EU GDPR

Art.32(1)(d)

EU DORA

Art.11(6)Art.13(6)

BIO2

5.29

RBI CSF

ITGRCA.29

FISC Security Guidelines

FISC.O5

HKMA TM-E-1

TME1.6.1TME1.6.3

MLPS 2.0

8.1.10.11

DNB Good Practice

DNB.11.2

NCA ECC

3-1

UAE IA

T12

CBB TM

TM-14

Qatar NIA

BC

CBUAE

CR-13

CBE CSF

OVM-2

SA JS2

JS2-7.5

CBN CSF

Part3.7

BoG CISD

CISD-BCM

BoM CTRM

5.2

CPMI-IOSCO PFMI

CG.RRPFMI.P17

NYDFS 500

500.16

HIPAA Security Rule

§164.308(a)(7)(i)§164.308(a)(7)(ii)(D)

ECB CROE

CROE.2.5.2

EBA ICT Guidelines

3.7.4

SEBI CSCRF

BCP-DRCCMP

BOT Cyber Resilience

Ch4.2

Solvency II

DR.266-BCPEIOPA-ICT-4.10

Lloyd's Minimum Standards

MS8.6MS9.2

NAIC Insurance Data Security

4F-b

FCA SYSC 13

SYSC 13.8.1

HITRUST CSF v11

12.b12.c

ISO 27799

17.1

NHS DSPT

NDG-7.1

MiCA

Art.62(6)

Basel SCO60

SCO60.53

SEC Custody (Digital Assets)

SEC-CD-12

ISO 17799 (legacy)

14.1.314.1.4

COBIT 4.1 (legacy)

DS4.6