Contingency Training CP-3


Overview:
The organization provides contingency training to information system users consistent with assigned roles and responsibilities:
a. Within [Assignment: organization-defined time period] of assuming a contingency role or responsibility;
b. When required by information system changes; and
c. [Assignment: organization-defined frequency] thereafter.


Supplemental Guidance:
Contingency training provided by organizations is linked to the assigned roles and responsibilities of organizational personnel to ensure that the appropriate content and level of detail is included in such training. For example, regular users may only need to know when and where to report for duty during contingency operations and if normal duties are affected; system administrators may require additional training on how to set up information systems at alternate processing and storage sites; and managers/senior leaders may receive more specific training on how to conduct mission-essential functions in designated off-site locations and how to establish communications with other governmental entities for purposes of coordination on contingency-related activities. Training for contingency roles/responsibilities reflects the specific continuity requirements in the contingency plan.


Related controls: AT-2, AT-3, CP-2, IR-2.


Action Items:
1) Ensure contingency training performed for users


Related Documents:
1) Contingency Plan Policy

2) Business Continuity Plans


Additional Guidance:
Moderate FedRAMP-Defined Assignment / Selection Parameters
CP-3 (a) [ten (10) days]
CP-3 (c) [at least annually]


Moderate Additional FedRAMP Requirements and Guidance
none



Article ID: 672
Created: September 29, 2022
Last Updated: September 29, 2022
Author: Matthew Burdick

Online URL: http://www.compliancewiki.org/article/contingency-training-cp-3-672.html