CP-04 Contingency Plan Testing And Exercises

Contingency Planning

Low Moderate High

Description

The organization: (i) tests and/or exercises the contingency plan for the information system [Assignment: organization-defined frequency, at least annually] using [Assignment: organization-defined tests and/or exercises] to determine the plan’s effectiveness and the organization’s readiness to execute the plan; and (ii) reviews the contingency plan test/exercise results and initiates corrective actions.\n

Supplemental Guidance

There are several methods for testing and/or exercising contingency plans to identify potential weaknesses (e.g., full-scale contingency plan testing, functional/tabletop exercises). The depth and rigor of contingency plan testing and/or exercises increases with the FIPS 199 impact level of the information system. Contingency plan testing and/or exercises also include a determination of the effects on organizational operations and assets (e.g., reduction in mission capability) and individuals arising due to contingency operations in accordance with the plan. NIST Special Publication 800-84 provides guidance on test, training, and exercise programs for information technology plans and capabilities.\n

Enhancements

\n

Compliance Mappings

ISO 27002:2022

5.295.30

COBIT 2019

DSS04.04DSS04.08

NIST CSF 2.0

ID.IM-02ID.IM-03

SOC 2 TSC

A1.3A1.3-POF1A1.3-POF2CC7.4-POF10CC7.5CC7.5-POF3CC7.5-POF6

ISO 17799 (legacy)

10.5.114.1.5

COBIT 4.1 (legacy)

DS4.2DS4.5