NIST Special Publication 800-34 Revision 1, Contingency Planning Guide for Federal Information Systems
Testing, Training, Exercises

NIST Special Publication 800-34 Revision 1, Contingency Planning Guide for Federal Information Systems NISTSP34-5: Plan Testing, Training, and Exercises (TTE)

Conduct Plan Testing, Training, and Exercises (TTE) per NIST SP 800-34 Rev 1 Section 3.6 + Appendix C (TTE Best Practices) + NIST SP 800-84 Guide to Test, Training, and Exercise Programs. Testing per Section 3.6.1 must (a) verify the plan documented procedures work as designed including notification + activation + system recovery + reconstitution + escalation + decision authority, (b) include functional tests (technical recovery of system components in a test environment) + tabletop exercises (discussion-based walkthroughs) + drills + full-scale exercises depending on impact level + organisational maturity + regulatory requirements per Appendix F. Training per Section 3.6.2 must (a) provide initial training for personnel with ISCP responsibilities covering plan content + procedures + contact information + decision authority + tools, (b) refresh training annually + after significant plan changes + on personnel turnover. Exercises per Section 3.6.3 must (a) be planned + scoped + documented + observed + after-actioned with lessons learned fed back to plan updates, (b) be conducted at frequency aligned with FIPS 199 impact level (Low annually + Moderate annually with technical recovery test + High annually with full functional test). Test documentation and after-action reports per Appendix C must capture objectives + scope + scenario + participants + observations + findings + recommendations + closure tracking.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 23 controls across 17 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • QMSR-820.10 Requirements for a Quality Management System - ISO 13485:2016 Sections 4-8 incorporation (§820.10)
  • QMSR-ISO13485-Sec8 Measurement, analysis and improvement (ISO 13485:2016 Section 8)
  • IATF16949-Clause10-Improvement-Nonconformity-CorrectiveAction-Problem-ErrorProof IATF 16949 Clause 10 - Improvement + Nonconformity + Corrective Action + Problem Solving + Error Proofing + Continual Improvement
  • IATF16949-Clause4-Context-Scope-CustomerSpecific-ProductSafety IATF 16949 Clause 4 - Context of Organization + QMS Scope + Customer Specific Requirements + Product Safety

SWIFT CSCF · 2 controls

  • SWIFTCSCF-1 Restrict Internet Access and Protect Critical Systems (Objective 1)
  • SWIFTCSCF-3 Physically Secure the Environment (Objective 3)
  • AS9100D-10.2 Nonconformity and Corrective Action
  • ACQS-8-3 Continuous Improvement
  • GGAP-IFA-AllFarmBase-Mgmt-Workers-Env-Trace GLOBALG.A.P. IFA v6 All Farm Base (AF): Management, Workers, Environment, Traceability and Food Safety
  • IMO-MSC-FAL-Recover-BackupRestore-ContinuityOfNavigation-LessonsLearned-Drills IMO MSC-FAL Recover Function - Backup and Restore + Continuity of Navigation + Continuity of Cargo Operations + Continuity of Propulsion + Lessons Learned + Drills + Resilience

ISO/IEC 27014:2020 · 1 control

  • 27014-5.6 Continuous improvement
  • ITAR-CompliancProgram-ICP-EmpoweredOfficial-Recordkeeping-5Years-Training-IT-Cloud-SupplyChain-Coord-EAR-OFAC-Wassenaar ITAR Compliance Program + Internal Compliance Program (ICP) + Empowered Official + 5-Year Recordkeeping + Training + IT/Cloud (GovCloud + Azure Gov + GCC High) + Supply Chain + Coord EAR + OFAC + Wassenaar + MTCR

NIST SP 800-30 · 1 control

  • NISTSP30-8 Risk Assessment Maintenance, Continuous Monitoring, and Integration with the RMF

NIST SP 800-37 · 1 control

  • NISTSP37-7 RMF Monitor Step: Continuous Monitoring and Ongoing Authorisation

NIST SP 800-39 · 1 control

  • NISTSP39-5 Risk Monitoring: Effectiveness, Changes, Compliance, and Reassessment Triggers
  • 2.5.2 Verification Activities

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 23 it maps to, and the evidence behind each claim, over MCP and REST.