|
controlCP-4

Contingency Plan Testing (CP-4)

Test the contingency plan for the system [organization-defined] using the following tests to determine the effectiveness of the plan and the readiness to execute the plan: [organization-defined]. Review the contingency plan test results; and Initiate corrective actions, if needed.

Security Baselines

LOWMODERATEHIGH
contingencydisaster-recoverybusiness-continuity

Why These Connect

Maps To8

These are equivalent or closely aligned requirements in other frameworks.

Baselined In3

This control is included in the linked security baseline (LOW, MODERATE, or HIGH).

Supports22

These related controls work together — a change to one may affect the others.

Enhances5

These enhancements add specific capabilities or refinements to the base control.

Cross-Framework Mappings(8)

ID.IM-02ID.IM-02Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
RC.RPIncident Recovery Plan Execution (RC.RP)Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
RC.RP-03RC.RP-03Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ISO 27001ISO/IEC 27001:20222 mappingsFinal
NIST OLIR informative reference — SP 800-53 Rev 5 to ISO/IEC 27001:2022
HIPAAHIPAA Security Rule1 mappingFinal
NIST OLIR informative reference — HIPAA Security Rule to SP 800-53 Rev 5
ID.IM-02ID.IM-02Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
RC.RPIncident Recovery Plan Execution (RC.RP)Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
RC.RP-03RC.RP-03Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5

Organization-Defined Parameters(3)

Assignmentorganization-defined frequency
Assignmentorganization-defined tests
Assignmentorganization-defined tests

Control Enhancements(5)