NIST 800-53 Rev. 5

CP-3(1): Contingency Training | Simulated Events

Control Text:

Incorporate simulated events into contingency training to facilitate effective response by personnel in crisis situations.

The use of simulated events creates an environment for personnel to experience actual threat events, including cyber-attacks that disable websites, ransomware attacks that encrypt organizational data on servers, hurricanes that damage or destroy organizational facilities, or hardware or software failures.

Related Controls

  • None