Cyber Resilience

NIST 800-53 r5 · Controls catalogue · Family CP

CP-3Contingency Training

Provide contingency training to system users consistent with assigned roles and responsibilities: Within {{ insert: param, cp-03_odp.01 }} of assuming a contingency role or responsibility; When required by system changes; and {{ insert: param, cp-03_odp.02 }} thereafter; and Review and update contingency training content {{ insert: param, cp-03_odp.03 }} and following {{ insert: param, cp-03_odp.04 }}.

Last updated: 20 August 2026 13:14 UTC

Implementations targeting this control (0)

ATT&CK techniques this control mitigates (0)

Weaknesses this control addresses (3)AI-assisted

CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.

CWE Name CVEs Why this control addresses it
CWE-754Improper Check for Unusual or Exceptional Conditions700+Training ensures users perform required checks for unusual or exceptional conditions as part of contingency roles, limiting attacker leverage from skipped validations.
CWE-755Improper Handling of Exceptional Conditions600+By preparing users for contingency scenarios, the control promotes proper handling of exceptional conditions instead of default or unsafe behaviors.
CWE-703Improper Check or Handling of Exceptional Conditions100+Contingency training equips users with defined procedures to check and respond to exceptional conditions during disruptions, reducing exploitation of mishandled errors.

Top CVEs where this control is the strongest mitigation

CVE Risk CVSS EPSS Match
No CVEs annotated to this control yet — the per-CVE backfill is in progress.

Other controls in family CP

CP-1 CP-10 CP-11 CP-12 CP-13 CP-2 CP-4 CP-5 CP-6 CP-7 CP-8 CP-9