Provide contingency training to system users consistent with assigned roles and responsibilities: Within [organization-defined] of assuming a continge
Scanned 9/3/2026
Install to Claude Code
npx -y skills add CyberStrikeus/CyberStrike --skill CP-3_contingency-training --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of CP 3 Contingency Training?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/cyberstrikeus-cp-3-contingency-training)More formats (shields.io, HTML) on the badges page.
---
name: "CP-3_contingency-training"
description: "Provide contingency training to system users consistent with assigned roles and responsibilities: Within [organization-defined] of assuming a continge"
category: "configuration"
version: "5.2.0"
author: "cyberstrike-official"
tags:
- nist
- sp800-53
- rev5
- cp-3
- cp
tech_stack:
- aws
- azure
- gcp
cwe_ids: []
chains_with:
- AT-2
- AT-3
- AT-4
- CP-2
- CP-4
- CP-8
- IR-2
- IR-4
- IR-9
prerequisites: []
severity_boost:
AT-2: "Chain with AT-2 for comprehensive security coverage"
AT-3: "Chain with AT-3 for comprehensive security coverage"
AT-4: "Chain with AT-4 for comprehensive security coverage"
---
# CP-3 Contingency Training
## High-Level Description
**Family:** Contingency Planning (CP)
**Framework:** NIST SP 800-53 Rev 5
Contingency training provided by organizations is linked to the assigned roles and responsibilities of organizational personnel to ensure that the appropriate content and level of detail is included in such training. For example, some individuals may only need to know when and where to report for duty during contingency operations and if normal duties are affected; system administrators may require additional training on how to establish systems at alternate processing and storage sites; and organizational officials may receive more specific training on how to conduct mission-essential functions in designated off-site locations and how to establish communications with other governmental entities for purposes of coordination on contingency-related activities. Training for contingency roles or responsibilities reflects the specific continuity requirements in the contingency plan. Events that may precipitate an update to contingency training content include, but are not limited to, contingency plan testing or an actual contingency (lessons learned), assessment or audit findings, security incidents or breaches, or changes in laws, executive orders, directives, regulations, policies, standards, and guidelines. At the discretion of the organization, participation in a contingency plan test or exercise, including lessons learned sessions subsequent to the test or exercise, may satisfy contingency plan training requirements.
## What to Check
- [ ] Verify CP-3 Contingency Training is documented in SSP
- [ ] Validate all 4 control requirements are implemented
- [ ] Confirm control is operating effectively
- [ ] Review evidence of continuous monitoring for CP-3
## How to Test
### Step 1: Review Documentation
Examine the System Security Plan (SSP) and related artifacts for CP-3 implementation details. Verify the organization has documented how this control is satisfied.
### Step 2: Validate Implementation
```
# For cloud environments, use cloud-audit-mcp tools
# For on-premises, review system configurations directly
# Example: Check if account management policies exist
grep -r "account.management\|access.control" /etc/security/ 2>/dev/null
```
### Step 3: Test Operating Effectiveness
Verify the control is actively functioning, not just documented. Check logs, configurations, and operational evidence.
## Tools
| Tool | Purpose | Usage |
| ------------- | --------------------------------- | ----- |
| Manual Review | Documentation and interview-based | N/A |
## Remediation Guide
### Control Statement
Provide contingency training to system users consistent with assigned roles and responsibilities:
Within [organization-defined] of assuming a contingency role or responsibility;
When required by system changes; and
[organization-defined] thereafter; and
Review and update contingency training content [organization-defined] and following [organization-defined].
### Implementation Guidance
Contingency training provided by organizations is linked to the assigned roles and responsibilities of organizational personnel to ensure that the appropriate content and level of detail is included in such training. For example, some individuals may only need to know when and where to report for duty during contingency operations and if normal duties are affected; system administrators may require additional training on how to establish systems at alternate processing and storage sites; and organizational officials may receive more specific training on how to conduct mission-essential functions in designated off-site locations and how to establish communications with other governmental entities for purposes of coordination on contingency-related activities. Training for contingency roles or responsibilities reflects the specific continuity requirements in the contingency plan. Events that may precipitate an update to contingency training content include, but are not limited to, contingency plan testing or an actual contingency (lessons learned), assessment or audit findings, security incidents or breaches, or changes in laws, executive orders, directives, regulations, policies, standards, and guidelines. At the discretion of the organization, participation in a contingency plan test or exercise, including lessons learned sessions subsequent to the test or exercise, may satisfy contingency plan training requirements.
## Risk Assessment
| Finding | Severity | Impact |
| ----------------------------------------- | -------- | ------------------------------- |
| CP-3 Contingency Training not implemented | Medium | Contingency Planning |
| CP-3 partially implemented | Low | Incomplete Contingency Planning |
## CWE Categories
| CWE ID | Title |
| ------ | --------------------- |
| N/A | No direct CWE mapping |
## References
- [NIST SP 800-53 Rev 5 - CP-3](https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=cp-3)
- [NIST SP 800-53A Rev 5 (Assessment Procedures)](https://csrc.nist.gov/pubs/sp/800/53/a/r5/final)
- [NIST SP 800-53 Rev 5 Full Catalog](https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final)
## Checklist
- [ ] Control documented in SSP
- [ ] Implementation evidence collected
- [ ] Operating effectiveness validated
- [ ] Continuous monitoring in place
- [ ] Related controls (AT-2, AT-3, AT-4, CP-2, CP-4) reviewed
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!