HOME

CP-3

CP-3 H M L
Description

The organization provides contingency training to information system users consistent with assigned roles and responsibilities:
a. Within [Assignment: organization-defined time period] of assuming a contingency role or responsibility;
b. When required by information system changes; and
c. [Assignment: organization-defined frequency] thereafter.

FedRAMP
  • H CP-3 (a) [ten (10) days] CP-3 (c) [at least annually]
  • M CP-3 (a) [ten (10) days] CP-3 (c) [at least annually]
  • L CP-3 (a) [ten (10) days] CP-3 (c) [at least annually]
DISA Cloud Computing SRG

a. at a maximum, 10 working days

c. at least annually

Source:
DoD RMF TAG

Supplemental Guidance

Contingency training provided by organizations is linked to the assigned roles and responsibilities of organizational personnel to ensure that the appropriate content and level of detail is included in such training. For example, regular users may only need to know
when and where to report for duty during contingency operations and if normal duties are affected; system administrators may require additional training on how to set up information systems at alternate processing and storage sites; and managers/senior leaders may receive more specific training on how to conduct mission-essential functions in designated off-site locations and how to establish communications with other governmental entities for purposes of coordination on
contingency-related activities. Training for contingency roles/responsibilities reflects the specific continuity requirements in the contingency plan.

Related Controls