|
controlCP-4
Contingency Plan Testing (CP-4)
Test the contingency plan for the system [organization-defined] using the following tests to determine the effectiveness of the plan and the readiness to execute the plan: [organization-defined]. Review the contingency plan test results; and Initiate corrective actions, if needed.
Security Baselines
LOWMODERATEHIGH
contingencydisaster-recoverybusiness-continuity
Why These Connect
Maps To8
These are equivalent or closely aligned requirements in other frameworks.
Baselined In3
This control is included in the linked security baseline (LOW, MODERATE, or HIGH).
Supports22
These related controls work together — a change to one may affect the others.
Enhances5
These enhancements add specific capabilities or refinements to the base control.
Related Controls(15)
CP-2Contingency Plan (CP-2)
LMH
CP-3Contingency Training (CP-3)LMH
AT-3Role-based Training (AT-3)LMH
CP-8Telecommunications Services (CP-8)MH
CP-9System Backup (CP-9)LMH
IR-3Incident Response Testing (IR-3)MH
IR-4Incident Handling (IR-4)LMH
PL-2System Security and Privacy Plans (PL-2)LMH
PM-14Testing, Training, and Monitoring (PM-14)SR-2Supply Chain Risk Management Plan (SR-2)LMH
CP-10System Recovery and Reconstitution (CP-10)LMH
IR-8Incident Response Plan (IR-8)LMH
PM-8Critical Infrastructure Plan (PM-8)SA-24Design For Cyber Resiliency (SA-24)SC-24Fail in Known State (SC-24)H
Cross-Framework Mappings(8)
ID.IM-02ID.IM-02Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
RC.RPIncident Recovery Plan Execution (RC.RP)Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
RC.RP-03RC.RP-03Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ISO 27001ISO/IEC 27001:20222 mappingsFinal
NIST OLIR informative reference — SP 800-53 Rev 5 to ISO/IEC 27001:2022
HIPAAHIPAA Security Rule1 mappingFinal
NIST OLIR informative reference — HIPAA Security Rule to SP 800-53 Rev 5
ID.IM-02ID.IM-02Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
RC.RPIncident Recovery Plan Execution (RC.RP)Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
RC.RP-03RC.RP-03Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
Organization-Defined Parameters(3)
Assignmentorganization-defined frequency
Assignmentorganization-defined tests
Assignmentorganization-defined tests