← Controls / CP

CP-04 Contingency Plan Testing

Contingency Planning

Low Moderate High

Description

a. Test the contingency plan for the system [Assignment: organization-defined frequency] using the following tests to determine the effectiveness of the plan and the readiness to execute the plan: [Assignment: organization-defined tests]. b. Review the contingency plan test results; and c. Initiate corrective actions, if needed.

Supplemental Guidance

Methods for testing contingency plans to determine the effectiveness of the plans and identify potential weaknesses include checklists, walk-through and tabletop exercises, simulations (parallel or full interrupt), and comprehensive exercises. Organizations conduct testing based on the requirements in contingency plans and include a determination of the effects on organizational operations, assets, and individuals due to contingency operations. Organizations have flexibility and discretion in the breadth, depth, and timelines of corrective actions.

Enhancements (5)

What NIST adds to this control. Select one to read its statement.

CP-04(01) Coordinate with Related Plans ModerateHigh

Coordinate contingency plan testing with organizational elements responsible for related plans.

CP-04(02) Alternate Processing Site High

Test the contingency plan at the alternate processing site: a. To familiarize contingency personnel with the facility and available resources; and b. To evaluate the capabilities of the alternate processing site to support contingency operations.

CP-04(03) Automated Testing

Test the contingency plan using [Assignment: organization-defined automated mechanisms].

CP-04(04) Full Recovery and Reconstitution

Include a full recovery and reconstitution of the system to a known state as part of contingency plan testing.

CP-04(05) Self-challenge

Employ [Assignment: organization-defined mechanisms] to [Assignment: organization-defined system or system component] to disrupt and adversely affect the system or system component.

Patterns that use this control (3)

Grouped by the emphasis each pattern gives it.

Compliance Mappings

ISO 27001:2022

A.5.29A.5.30

ISO 27002:2022

5.295.30

COBIT 2019

DSS04

CIS Controls v8

CIS 11.5

NIST CSF 2.0

ID.IM-02ID.IM-04RC.RP-03

SOC 2 TSC

A1.3CC7.4-POF10CC7.5

CSA CCM v4

BCR-04BCR-06BCR-10

CSA AICM v1

BCR-04BCR-06BCR-10

NIS2 Directive

Art. 21(2)(c)

PRA Operational Resilience

SS1/21-6.1SS1/21-6.2SS2/21-10.1

MAS TRM

8

BSI IT-Grundschutz

DER.4

ANSSI

Hygiene.35SecNumCloud.18.2

FINMA Circular 2023/1

IV.E(94)IV.E(95)IV.E(96)IV.F(97)

OSFI B-13

B-13.2.6B-13.3.5

EU GDPR

Art.32(1)(d)

EU DORA

Art.11(6)Art.11(7)

BIO2

5.295.30

RBI CSF

ITGRCA.29

FISC Security Guidelines

FISC.O5

HKMA TM-E-1

TME1.6.3

MLPS 2.0

8.1.10.98.1.10.11

DNB Good Practice

DNB.11.2

SWIFT CSCF

SWIFT.7.4A

NCA ECC

3-13-2

UAE IA

T12

CBB TM

TM-14

Qatar NIA

BC

CBUAE

CR-13

CBE CSF

OVM-2

SA JS2

JS2-7.5

CBN CSF

Part3.6Part3.7Part3.8

BoG CISD

CISD-BCMCISD-X

BoM CTRM

5.2

IOSCO Cyber Resilience

LE-1PFMI-17RR-5TEST-1TEST-4TEST-5

CPMI-IOSCO PFMI

CG.RRCG.TEPFMI.P17

NYDFS 500

500.16

HIPAA Security Rule

§164.308(a)(7)(i)§164.308(a)(7)(ii)(D)

ECB CROE

CROE.2.5.2CROE.2.6.1

EBA ICT Guidelines

3.7.4

SEBI CSCRF

BCP-DRCCMPRC.IMRC.RP

BOT Cyber Resilience

Ch4.2

NERC CIP

CIP-009-6

10 CFR 73.54

RG5.71-B-CP

DOE C2M2 v2.1

RESPONSE

API 1164

Sec 11

AWIA

Sec 2013(b)

IAEA NSS 17-T

Sec 8

Solvency II

DR.266-BCPDR.274EIOPA-ICT-4.10

Lloyd's Minimum Standards

CRM.3MS8.6MS9.2

NAIC Insurance Data Security

4F-b

PRA SS1/23

P5.4

FCA SYSC 13

SYSC 13.8.1SYSC 13.8.2SYSC 13.9.5

HITRUST CSF v11

12.b12.c

ISO 27799

17.1

NHS DSPT

NDG-7.1NDG-7.3

CCSS v9.0

1.06.3

MiCA

Art.62(6)Art.68(5)

Basel SCO60

SCO60.23SCO60.53

BSSC Standards

GSP-06

SEC Custody (Digital Assets)

SEC-CD-12SEC-CD-13

ISO 17799 (legacy)

10.5.114.1.5

COBIT 4.1 (legacy)

DS4.2DS4.5