Information Technology Reference
In-Depth Information
Category/
Subcategory/ 
Element
Control 
Reference
Control Summary
Interpretation
CP-4
Contingency plan
testing and
exercises
The organization: (i) tests and
exercises the contingency plan for
the information system
[assignment: organization-
defined frequency, at least
annually] using [assignment:
organization-defined tests and
exercises] to determine the plan's
effectiveness and the
organization's readiness to
execute the plan; and (ii) reviews
the contingency plan test/exercise
results and initiates corrective
actions.
CP-5
Contingency plan
update
The organization reviews the
contingency plan for the
information system [assignment:
organization-defined frequency,
at least annually] and revises the
plan to address system/
organizational changes or
problems encountered during
plan implementation, execution,
or testing.
CP-6
Alternate storage site The organization identifies an
alternate storage site and initiates
necessary agreements to permit
the storage of information system
backup information.
CP-7
Alternate processing
site
The organization identifies an
alternate processing site and
initiates necessary agreements to
permit the resumption of
information system operations for
critical mission/business functions
within [assignment: organization-
defined time period] when the
primary processing capabilities
are unavailable.
 
Search WWH ::




Custom Search