Organizational Control: Contingency Training
Control ID: CP-3 Contingency Training | Family: Contingency Planning | Source: NIST 800-53r4 |
Control: The organization provides contingency training to information system users consistent with assigned roles and responsibilities:
|
||
Supplemental Guidance: Contingency training provided by organizations is linked to the assigned roles and responsibilities of organizational personnel to ensure that the appropriate content and level of detail is included in such training. For example, regular users may only need to know when and where to report for duty during contingency operations and if normal duties are affected; system administrators may require additional training on how to set up information systems at alternate processing and storage sites; and managers/senior leaders may receive more specific training on how to conduct mission-essential functions in designated off-site locations and how to establish communications with other governmental entities for purposes of coordination on contingency-related activities. Training for contingency roles/responsibilities reflects the specific continuity requirements in the contingency plan. Related Controls: AT-2, AT-3, CP-2, IR-2 |
||
Control Enhancements:
(1) Contingency Training | Simulated Events The organization incorporates simulated events into contingency training to facilitate effective response by personnel in crisis situations. Supplemental Guidance: Related Controls: N/A (2) Contingency Training | Automated Training Environments The organization employs automated mechanisms to provide a more thorough and realistic contingency training environment. Supplemental Guidance: Related Controls: N/A |
||
References: Federal Continuity Directive 1; NIST Special Publications 800-16, 800-50. | ||
Mechanisms:
|
||
Protocol Implementation Conformance Statements: N/A |