Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search exact control and technique identifiers, Cyber Wiki articles, framework records, playbooks, books, podcasts, Academy courses, and individual lessons.

NIST SP 800-53 Learning Center

CP-3 — Contingency Training

Read the official control and assessment content, then use the separately labeled Bare Metal Cyber perspective to connect the requirement to implementation, evidence, and sustained operation.

2Enhancements
4Parameters
3Baseline memberships
3Assessment methods

CP — Contingency Planning · NIST SP 800-53 Release 5.2.0

LowModerateHigh
Official NIST control content

Control statement

  1. a.Provide contingency training to system users consistent with assigned roles and responsibilities:
    1. 1.Within [Organization-defined: time period] of assuming a contingency role or responsibility;
    2. 2.When required by system changes; and
    3. 3.[Organization-defined: frequency] thereafter; and
  2. b.Review and update contingency training content [Organization-defined: frequency] and following [Organization-defined: events].
Official NIST discussion

Discussion

Contingency training provided by organizations is linked to the assigned roles and responsibilities of organizational personnel to ensure that the appropriate content and level of detail is included in such training. For example, some individuals may only need to know when and where to report for duty during contingency operations and if normal duties are affected; system administrators may require additional training on how to establish systems at alternate processing and storage sites; and organizational officials may receive more specific training on how to conduct mission-essential functions in designated off-site locations and how to establish communications with other governmental entities for purposes of coordination on contingency-related activities. Training for contingency roles or responsibilities reflects the specific continuity requirements in the contingency plan. Events that may precipitate an update to contingency training content include, but are not limited to, contingency plan testing or an actual contingency (lessons learned), assessment or audit findings, security incidents or breaches, or changes in laws, executive orders, directives, regulations, policies, standards, and guidelines. At the discretion of the organization, participation in a contingency plan test or exercise, including lessons learned sessions subsequent to the test or exercise, may satisfy contingency plan training requirements.

Official OSCAL parameters

Organization-defined parameters

These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.

time periodthe time period within which to provide contingency training after assuming a contingency role or responsibility is defined;
frequencyfrequency at which to provide training to system users with a contingency role or responsibility is defined;
frequencyfrequency at which to review and update contingency training content is defined;
eventsevents necessitating review and update of contingency training are defined;
Original Bare Metal Cyber perspective

From control text to operational evidence

Use Contingency Training as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to resilient operations, recovery priorities, alternate capabilities, and tested restoration.

Implementation workflow

  • Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
  • Resolve each organization-defined parameter before declaring the control implemented.
  • Document how the implementation satisfies every clause of the official control statement.
  • Collect evidence as a normal byproduct of operation rather than only before an assessment.
  • Review exceptions, changes, and monitoring results on a risk-based cadence.

Evidence examples

  • contingency and recovery plans
  • backup success and restoration-test records
  • exercise after-action reports
  • alternate processing or communications agreements

Common failure patterns

  • backups never restored in testing
  • recovery priorities not tied to mission impact
  • plans dependent on unavailable people or facilities
  • exercise findings not tracked to closure

Questions practitioners should ask

  • What risk decision is this control intended to support in this system?
  • Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
  • Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
  • What event or threshold requires the implementation to be reviewed or changed?
Official NIST SP 800-53A content

Assessment objectives and methods

Show the assessment objective
  1. CP-03a.
    1. CP-03a.01contingency training is provided to system users consistent with assigned roles and responsibilities within [Organization-defined: time period] of assuming a contingency role or responsibility;
    2. CP-03a.02contingency training is provided to system users consistent with assigned roles and responsibilities when required by system changes;
    3. CP-03a.03contingency training is provided to system users consistent with assigned roles and responsibilities [Organization-defined: frequency] thereafter;
  2. CP-03b.
    1. CP-03b.[01]the contingency plan training content is reviewed and updated [Organization-defined: frequency];
    2. CP-03b.[02]the contingency plan training content is reviewed and updated following [Organization-defined: events].

Examine

  • Contingency planning policy
  • procedures addressing contingency training
  • contingency plan
  • contingency training curriculum
  • contingency training material
  • contingency training records
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with contingency planning, plan implementation, and training responsibilities
  • organizational personnel with information security responsibilities

Test

  • Organizational processes for contingency training
Official relationships

Related controls

These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.

Official NIST enhancements

Control enhancements

Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.

Official NIST control enhancement

CP-3(1) — Simulated Events

High

Incorporate simulated events into contingency training to facilitate effective response by personnel in crisis situations.

Official discussion

The use of simulated events creates an environment for personnel to experience actual threat events, including cyber-attacks that disable websites, ransomware attacks that encrypt organizational data on servers, hurricanes that damage or destroy organizational facilities, or hardware or software failures.

Assessment objectives and methods

simulated events are incorporated into contingency training to facilitate effective response by personnel in crisis situations.

Examine

  • Contingency planning policy
  • procedures addressing contingency training
  • contingency plan
  • contingency training curriculum
  • contingency training material
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with contingency planning, plan implementation, and training responsibilities
  • organizational personnel with information security responsibilities

Test

  • Organizational processes for contingency training
  • mechanisms for simulating contingency events
Official NIST control enhancement

CP-3(2) — Mechanisms Used in Training Environments

Employ mechanisms used in operations to provide a more thorough and realistic contingency training environment.

Official discussion

Operational mechanisms refer to processes that have been established to accomplish an organizational goal or a system that supports a particular organizational mission or business objective. Actual mission and business processes, systems, and/or facilities may be used to generate simulated events and enhance the realism of simulated events during contingency training.

Assessment objectives and methods

mechanisms used in operations are employed to provide a more thorough and realistic contingency training environment.

Examine

  • Contingency planning policy
  • procedures addressing contingency training
  • contingency plan
  • contingency training curriculum
  • contingency training material
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with contingency planning, plan implementation, and training responsibilities
  • organizational personnel with information security responsibilities

Test

  • Organizational processes for contingency training
  • mechanisms for providing contingency training environments
Source record

Authoritative sources