NIST 800-53 REV 5 • CONTINGENCY PLANNING

CP-5Contingency Plan Update

CMMC Practice Mapping

No direct CMMC mapping

NIST 800-171 Mapping

No direct NIST 800-171 mapping

Related Controls

No related controls listed

Practitioner Notes

This control was incorporated into CP-2. It required that your contingency plan be reviewed and updated regularly to reflect changes in your environment, lessons learned, and new threats.

Example 1: After every contingency plan test or real incident, conduct a lessons learned session and update the plan to address any gaps or procedural issues discovered.

Example 2: Review your contingency plan whenever significant system changes occur — like migrating to a new cloud platform or adding a new critical business application.