STIGhubSTIGhub
STIGsRMF ControlsCompare
STIGhub— A free STIG search and compliance tool·STIGs updated 3 days ago
Powered by Pylon·Privacy·Terms·© 2026 Beacon Cloud Solutions, Inc.
← All Controls

CP-4

Contingency PlanningRev 5organization

Contingency Plan Testing

Baselines:LowModerateHigh

Control Statement

a. Test the contingency plan for the system [Assignment: frequency] using the following tests to determine the effectiveness of the plan and the readiness to execute the plan: [Assignment: organization-defined tests]. b. Review the contingency plan test results; and c. Initiate corrective actions, if needed.

Supplemental Guidance

Methods for testing contingency plans to determine the effectiveness of the plans and identify potential weaknesses include checklists, walk-through and tabletop exercises, simulations (parallel or full interrupt), and comprehensive exercises. Organizations conduct testing based on the requirements in contingency plans and include a determination of the effects on organizational operations, assets, and individuals due to contingency operations. Organizations have flexibility and discretion in the breadth, depth, and timelines of corrective actions.

Related Controls (10)

AT-3CP-2CP-3CP-8CP-9IR-3IR-4PL-2PM-14SR-2

CCI Identifiers (8)

CCI-000490Defines the frequency with which to test the contingency plan for the system.CCI-000496Review the contingency plan test results.CCI-000491The organization defines the frequency to exercise the contingency plan for the information system.CCI-000492Defines the contingency plan tests to be conducted for the system.CCI-000493The organization defines contingency plan exercises to be conducted for the information system.CCI-000494Test the contingency plan for the system in accordance with organization-defined frequency using organization-defined tests to determine the effectiveness of the plan and the organizational readiness to execute the plan.CCI-000495The organization exercises the contingency plan using organization-defined exercises in accordance with organization-defined frequency.CCI-000497Initiate corrective actions, if needed, after reviewing the contingency plan test results.

Linked STIG Checks (0)

No STIG checks reference this control.