Cyber Posture

NIST 800-53 r5 · Controls catalogue · Family CP

CP-3Contingency Training

Provide contingency training to system users consistent with assigned roles and responsibilities: Within {{ insert: param, cp-03_odp.01 }} of assuming a contingency role or responsibility; When required by system changes; and {{ insert: param, cp-03_odp.02 }} thereafter; and Review and update contingency training content {{ insert: param, cp-03_odp.03 }} and following {{ insert: param, cp-03_odp.04 }}.

Last updated: 09 May 2026 03:25 UTC

Implementations targeting this control (0)

ATT&CK techniques this control mitigates (0)

Weaknesses this control addresses (3)AI

CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.

CWE Name CVEs Why this control addresses it
CWE-754Improper Check for Unusual or Exceptional Conditions697Training ensures users perform required checks for unusual or exceptional conditions as part of contingency roles, limiting attacker leverage from skipped validations.
CWE-755Improper Handling of Exceptional Conditions662By preparing users for contingency scenarios, the control promotes proper handling of exceptional conditions instead of default or unsafe behaviors.
CWE-703Improper Check or Handling of Exceptional Conditions146Contingency training equips users with defined procedures to check and respond to exceptional conditions during disruptions, reducing exploitation of mishandled errors.

Top CVEs where this control is the strongest mitigation

CVE Risk CVSS EPSS Match
No CVEs annotated to this control yet — the per-CVE backfill is in progress.

Other controls in family CP

CP-1 CP-10 CP-11 CP-12 CP-13 CP-2 CP-4 CP-5 CP-6 CP-7 CP-8 CP-9