STIGhubSTIGhub
STIGsRMF ControlsCompare
STIGhub— A free STIG search and compliance tool·STIGs updated 3 days ago
Powered by Pylon·Privacy·Terms·© 2026 Beacon Cloud Solutions, Inc.
← All Controls

CP-3

Contingency PlanningRev 5organization

Contingency Training

Baselines:LowModerateHigh

Control Statement

a. Provide contingency training to system users consistent with assigned roles and responsibilities: 1. Within [Assignment: time period] of assuming a contingency role or responsibility; 2. When required by system changes; and 3. [Assignment: frequency] thereafter; and b. Review and update contingency training content [Assignment: frequency] and following [Assignment: events].

Supplemental Guidance

Contingency training provided by organizations is linked to the assigned roles and responsibilities of organizational personnel to ensure that the appropriate content and level of detail is included in such training. For example, some individuals may only need to know when and where to report for duty during contingency operations and if normal duties are affected; system administrators may require additional training on how to establish systems at alternate processing and storage sites; and organizational officials may receive more specific training on how to conduct mission-essential functions in designated off-site locations and how to establish communications with other governmental entities for purposes of coordination on contingency-related activities. Training for contingency roles or responsibilities reflects the specific continuity requirements in the contingency plan. Events that may precipitate an update to contingency training content include, but are not limited to, contingency plan testing or an actual contingency (lessons learned), assessment or audit findings, security incidents or breaches, or changes in laws, executive orders, directives, regulations, policies, standards, and guidelines. At the discretion of the organization, participation in a contingency plan test or exercise, including lessons learned sessions subsequent to the test or exercise, may satisfy contingency plan training requirements.

Related Controls (9)

AT-2AT-3AT-4CP-2CP-4CP-8IR-2IR-4IR-9

CCI Identifiers (9)

CCI-000486Provide contingency training to system users consistent with assigned roles and responsibilities within an organization-defined time period of assuming a contingency role or responsibility.CCI-000487Provide contingency training to system users consistent with assigned roles and responsibilities in accordance with organization-defined frequency.CCI-002833Defines the time period that contingency training is to be provided to system users consistent with assigned roles and responsibilities within assuming a contingency role or responsibility.CCI-002834Provide contingency training to system users consistent with assigned roles and responsibilities when required by system changes.CCI-004010Review and update contingency training content on an organization-defined frequency.CCI-004011Defines the frequency the contingency training content will be reviewed and updated.CCI-004012Review and update contingency training content following organization-defined events.CCI-004013Defines the events for which the contingency training content will be reviewed and updated.

Linked STIG Checks (0)

No STIG checks reference this control.

CCI-000485Defines the frequency of contingency training to system users.