# CP-04 Contingency Plan Testing

NIST SP 800-53 control. Family: CP Contingency Planning. Function: corrective. Baselines: low, moderate, high. Mapping licence: CC BY-SA 4.0.

Statement: a. Test the contingency plan for the system [Assignment: organization-defined frequency] using the following tests to determine the effectiveness of the plan and the readiness to execute the plan: [Assignment: organization-defined tests]. b. Review the contingency plan test results; and c. Initiate corrective actions, if needed.
Guidance: Methods for testing contingency plans to determine the effectiveness of the plans and identify potential weaknesses include checklists, walk-through and tabletop exercises, simulations (parallel or full interrupt), and comprehensive exercises. Organizations conduct testing based on the requirements in contingency plans and include a determination of the effects on organizational operations, assets, and individuals due to contingency operations. Organizations have flexibility and discretion in the breadth, depth, and timelines of corrective actions.

## Enhancements (5)
- CP-04(01) Coordinate with Related Plans. Baselines: moderate, high
- CP-04(02) Alternate Processing Site. Baselines: high
- CP-04(03) Automated Testing
- CP-04(04) Full Recovery and Reconstitution
- CP-04(05) Self-challenge
Each enhancement's statement: /api/v1/controls/CP-04?fields=enhancements

## Patterns that use it (3)
- Critical (1): SP-034 Cyber Resilience
- Standard (2): SP-001 Client Module; SP-002 Server Module

## Clauses by framework (61 frameworks)
- iso_27001_2022: A.5.29, A.5.30
- iso_27002_2022: 5.29, 5.30
- cobit_2019: DSS04
- nist_csf_2: ID.IM-02, ID.IM-04, RC.RP-03. OSA's own, not in NIST's crosswalk: ID.IM-04
- cis_controls_v8: CIS 11.5
- soc2_tsc: A1.3, CC7.4-POF10, CC7.5
- nis2: Art. 21(2)(c)
- mas_trm: 8
- pra_op_resilience: SS1/21-6.1, SS1/21-6.2, SS2/21-10.1
- bsi_grundschutz: DER.4
- anssi: Hygiene.35, SecNumCloud.18.2
- osfi_b13: B-13.2.6, B-13.3.5
- finma_circular: IV.E(94), IV.E(95), IV.E(96), IV.F(97)
- gdpr: Art.32(1)(d)
- dora: Art.11(6), Art.11(7)
- bio2: 5.29, 5.30
- rbi_csf: ITGRCA.29
- fisc: FISC.O5
- hkma_tme1: TME1.6.3
- mlps_2: 8.1.10.9, 8.1.10.11
- dnb_good_practice: DNB.11.2
- swift_cscf: SWIFT.7.4A
- cbb_tm: TM-14
- cbuae: CR-13
- nca_ecc: 3-1, 3-2
- qatar_nia: BC
- uae_ia: T12
- bog_cisd: CISD-BCM, CISD-X
- bom_ctrm: 5.2
- cbe_csf: OVM-2
- cbn_csf: Part3.6, Part3.7, Part3.8
- sa_js2: JS2-7.5
- bot_cyber: Ch4.2
- cpmi_pfmi: CG.RR, CG.TE, PFMI.P17
- eba_ict: 3.7.4
- ecb_croe: CROE.2.5.2, CROE.2.6.1
- hipaa_sr: §164.308(a)(7)(i), §164.308(a)(7)(ii)(D)
- iosco_cyber: LE-1, PFMI-17, RR-5, TEST-1, TEST-4, TEST-5
- nydfs_500: 500.16
- sebi_cscrf: BCP-DR, CCMP, RC.IM, RC.RP
- nerc_cip: CIP-009-6
- nrc_73_54: RG5.71-B-CP
- doe_c2m2: RESPONSE
- api_1164: Sec 11
- awia: Sec 2013(b)
- iaea_nss: Sec 8
- fca_sysc_13: SYSC 13.8.1, SYSC 13.8.2, SYSC 13.9.5
- hitrust_csf: 12.b, 12.c
- iso_27799: 17.1
- lloyds_ms: CRM.3, MS8.6, MS9.2
- naic_ds: 4F-b
- nhs_dspt: NDG-7.1, NDG-7.3
- pra_ss1_23: P5.4
- solvency_ii: DR.266-BCP, DR.274, EIOPA-ICT-4.10
- csa_ccm_v4: BCR-04, BCR-06, BCR-10
- csa_aicm: BCR-04, BCR-06, BCR-10
- ccss_v9: 1.06.3
- mica: Art.62(6), Art.68(5)
- basel_sco60: SCO60.23, SCO60.53
- bssc: GSP-06
- sec_custody_digital: SEC-CD-12, SEC-CD-13
OSA's mapping for iso_27001_2022 and nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/CP-04
- Clauses only: /api/v1/controls/CP-04?fields=mappings
- Page for people: /controls/cp-04/
