Under active development Content is continuously updated and improved

CP-3Contingency Training

PBMM (P3)
Secret (P3)
Operational

>Control Description

(A) The organization provides contingency training to information system users consistent with assigned roles and responsibilities within organization-defined time period of assuming a contingency role or responsibility. (B) The organization provides contingency training to information system users consistent with assigned roles and responsibilities when required by information system changes. (C) The organization provides contingency training to information system users consistent with assigned roles and responsibilities organization-defined frequency thereafter.

>Supplemental Guidance

Contingency training provided by organizations is linked to the assigned roles and responsibilities of organizational personnel to ensure that the appropriate content and level of detail is included in such training. For example, regular users may only need to know when and where to report for duty during contingency operations and if normal duties are affected; system administrators may require additional training on how to set up information systems at alternate processing and storage sites; and managers/senior leaders may receive more specific training on how to conduct mission-essential functions in designated off-site locations and how to establish communications with other governmental entities for purposes of coordination on contingency-related activities. Training for contingency roles/responsibilities reflects the specific continuity requirements in the contingency plan.

Related controls: AT-2, AT-3, CP-2, IR-2

>Tailoring Guidance

This security control/enhancement is considered to be best practice. Consequently, inclusion in a departmental profile is strongly encouraged in most cases.

Ask AI

Configure your API key to use AI features.