NIST SP 800-53 Rev 5
CP - Contingency Planning

NIST SP 800-53 Rev 5 NIST800-CP-4: CP-4 Contingency Plan Testing

a. Test the contingency plan for the system [Assignment: organization-defined frequency] using the following tests to determine the effectiveness of the plan and the readiness to execute the plan: [Assignment: organization-defined tests]. b. Review the contingency plan test results; and c. Initiate corrective actions, if needed.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 54 controls across 27 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-ID.IM-01 Improvements are identified from evaluations
  • NIST-CSF-ID.IM-03 Improvements are identified from execution of operational processes, procedures, and activities
  • NIST-CSF-PR.DS-11 Backups of data are created, protected, maintained, and tested
  • NIST-CSF-RC.CO-03 Recovery activities and progress in restoring operational capabilities are communicated to designated internal and external stakeholders
  • NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process
  • NIST-CSF-RC.RP-02 Recovery actions are selected, scoped, prioritized, and performed

FedRAMP High · 4 controls

  • CP-2(3) Resume Mission and Business Functions
  • CP-4 Contingency Plan Testing
  • CP-4(1) Coordinate with Related Plans
  • IR-3 Incident Response Testing

FedRAMP Moderate · 4 controls

  • CP-2(3) Resume Mission and Business Functions
  • CP-4 Contingency Plan Testing
  • CP-4(1) Coordinate with Related Plans
  • IR-3 Incident Response Testing

ISO 22301:2019 · 3 controls

  • 8.4 Business continuity plans and procedures
  • 8.5 Exercise programme
  • 8.6 Evaluation of business continuity documentation and capabilities

ISO 27002:2022 · 3 controls

  • 5.24 Information security incident management planning and preparation
  • 5.29 Information security during disruption
  • 5.30 ICT readiness for business continuity
  • CPS230-33 Systematic BCP Testing Program
  • CPS230-34 Tailoring of the Testing Program
  • ASD37-34 Regular backups (Essential)
  • ASD37-35 Business continuity and disaster recovery plans (Very Good)

C5 (Germany) · 2 controls

  • C5-BCM-04 Verification, updating and testing of the business continuity
  • C5-OPS-08 Data Backup and Recovery - Regular Testing

CIS Controls v8 · 2 controls

DORA · 2 controls

  • DORA-Art.11 Response and recovery
  • DORA-Art.24 General requirements for the performance of digital operational resilience testing

HIPAA Security Rule · 2 controls

ISO 27001:2022 · 2 controls

  • 5.29 Information security during disruption
  • 5.30 ICT readiness for business continuity

ISO 27701:2019 · 2 controls

  • 6.14 Information security aspects of business continuity management
  • 6.14.1 Information security continuity

NIST SP 800-66 Rev 2 · 2 controls

SOC 2 · 2 controls

  • SOC2-A1.3 A1.3 Testing recovery plan procedures
  • SOC2-CC9.1 CC9.1 Mitigating risks of business disruption
  • E8-BACKUP-ML1 Regular Backups (ML1)
  • ANSSI-HYG-37 Define and Apply a Backup Policy for Critical Components

APRA CPS 234 · 1 control

  • CPS234-32 Annual Review and Testing of Response Plans
  • CFTC-SS-11 Testing and Review of Business Continuity and Disaster Recovery Capabilities

NIS2 Directive · 1 control

  • Art.21.2.c Business continuity, backup management, disaster recovery and crisis management
  • CP-4 CP-4 Contingency Plan Testing
  • CP-4 CP-4 Contingency Plan Testing
  • CP-4 CP-4 Contingency Plan Testing

PCI DSS 4.0 · 1 control

  • 12.10.6 12.10.6 Plan evolved from lessons learned and industry developments

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in CP - Contingency Planning

You are reading one control. How much of NIST SP 800-53 Rev 5 have you already done?

NIST SP 800-53 Rev 5 NIST800-CP-4 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST SP 800-53 Rev 5 your existing evidence covers. Hold ISO 27001:2022 and 163 of 1014 NIST SP 800-53 Rev 5 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 342 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 54 it maps to, and the evidence behind each claim, over MCP and REST.