Contingency Plan
✓ LOW ✓ MODERATE ✓ HIGHRequirements NIST SOURCE
- 1.Identifies essential mission and business functions and associated contingency requirements;
- 2.Provides recovery objectives, restoration priorities, and metrics;
- 3.Addresses contingency roles, responsibilities, assigned individuals with contact information;
- 4.Addresses maintaining essential mission and business functions despite a system disruption, compromise, or failure;
- 5.Addresses eventual, full system restoration without deterioration of the controls originally planned and implemented;
- 6.Addresses the sharing of contingency information; and
- 7.Is reviewed and approved by [organization-defined personnel or roles];
Requirement Context
This element is part of CP-2 — Contingency Plan. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Requirement Context
This element is part of CP-2 — Contingency Plan. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Requirement Context
This element is part of CP-2 — Contingency Plan. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Requirement Context
This element is part of CP-2 — Contingency Plan. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Requirement Context
This element is part of CP-2 — Contingency Plan. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Requirement Context
This element is part of CP-2 — Contingency Plan. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Requirement Context
This element is part of CP-2 — Contingency Plan. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Requirement Context
This element is part of CP-2 — Contingency Plan. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Discussion (NIST Supplemental Guidance)
Contingency planning for systems is part of an overall program for achieving continuity of operations for organizational mission and business functions. Contingency planning addresses system restoration and implementation of alternative mission or business processes when systems are compromised or breached. Contingency planning is considered throughout the system development life cycle and is a fundamental part of the system design. Systems can be designed for redundancy, to provide backup capabilities, and for resilience. Contingency plans reflect the degree of restoration required for organizational systems since not all systems need to fully recover to achieve the level of continuity of operations desired. System recovery objectives reflect applicable laws, executive orders, directives, regulations, policies, standards, guidelines, organizational risk tolerance, and system impact level. Actions addressed in contingency plans include orderly system degradation, system shutdown, fallback to a manual mode, alternate information flows, and operating in modes reserved for when systems are under attack. By coordinating contingency planning with incident handling activities, organizations ensure that the necessary planning activities are in place and activated in the event of an incident. Organizations consider whether continuity of operations during an incident conflicts with the capability to automatically disable the system, as specified in IR-4(5) . Incident response planning is part of contingency planning for organizations and is addressed in the IR (Incident Response) family.
Enhancements NIST SOURCE
CP-2(1) Coordinate with Related Plans LOW ✓ MODERATE ✓ HIGH
Coordinate contingency plan development with organizational elements responsible for related plans.
Discussion
Plans that are related to contingency plans include Business Continuity Plans, Disaster Recovery Plans, Critical Infrastructure Plans, Continuity of Operations Plans, Crisis Communications Plans, Insider Threat Implementation Plans, Data Breach Response Plans, Cyber Incident Response Plans, Breach Response Plans, and Occupant Emergency Plans.
CP-2(2) Capacity Planning LOW MODERATE ✓ HIGH
Conduct capacity planning so that necessary capacity for information processing, telecommunications, and environmental support exists during contingency operations.
Discussion
Capacity planning is needed because different threats can result in a reduction of the available processing, telecommunications, and support services intended to support essential mission and business functions. Organizations anticipate degraded operations during contingency operations and factor the degradation into capacity planning. For capacity planning, environmental support refers to any environmental factor for which the organization determines that it needs to provide support in a contingency situation, even if in a degraded state. Such determinations are based on an organizational assessment of risk, system categorization (impact level), and organizational risk tolerance.
CP-2(3) Resume Mission and Business Functions LOW ✓ MODERATE ✓ HIGH
Plan for the resumption of [one of: all; essential] mission and business functions within [time period] of contingency plan activation.
Discussion
Organizations may choose to conduct contingency planning activities to resume mission and business functions as part of business continuity planning or as part of business impact analyses. Organizations prioritize the resumption of mission and business functions. The time period for resuming mission and business functions may be dependent on the severity and extent of the disruptions to the system and its supporting infrastructure.
CP-2(4) Resume All Mission and Business Functions WITHDRAWN
Withdrawn. Incorporated into CP-2(3).
CP-2(5) Continue Mission and Business Functions LOW MODERATE ✓ HIGH
Plan for the continuance of [one of: all; essential] mission and business functions with minimal or no loss of operational continuity and sustains that continuity until full system restoration at primary processing and/or storage sites.
Discussion
Organizations may choose to conduct the contingency planning activities to continue mission and business functions as part of business continuity planning or business impact analyses. Primary processing and/or storage sites defined by organizations as part of contingency planning may change depending on the circumstances associated with the contingency.
CP-2(6) Alternate Processing and Storage Sites LOW MODERATE HIGH
Plan for the transfer of [one of: all; essential] mission and business functions to alternate processing and/or storage sites with minimal or no loss of operational continuity and sustain that continuity through system restoration to primary processing and/or storage sites.
Discussion
Organizations may choose to conduct contingency planning activities for alternate processing and storage sites as part of business continuity planning or business impact analyses. Primary processing and/or storage sites defined by organizations as part of contingency planning may change depending on the circumstances associated with the contingency.
CP-2(7) Coordinate with External Service Providers LOW MODERATE HIGH
Coordinate the contingency plan with the contingency plans of external service providers to ensure that contingency requirements can be satisfied.
Discussion
When the capability of an organization to carry out its mission and business functions is dependent on external service providers, developing a comprehensive and timely contingency plan may become more challenging. When mission and business functions are dependent on external service providers, organizations coordinate contingency planning activities with the external entities to ensure that the individual plans reflect the overall contingency needs of the organization.
CP-2(8) Identify Critical Assets LOW ✓ MODERATE ✓ HIGH
Identify critical system assets supporting [one of: all; essential] mission and business functions.
Discussion
Organizations may choose to identify critical assets as part of criticality analysis, business continuity planning, or business impact analyses. Organizations identify critical system assets so that additional controls can be employed (beyond the controls routinely implemented) to help ensure that organizational mission and business functions can continue to be conducted during contingency operations. The identification of critical information assets also facilitates the prioritization of organizational resources. Critical system assets include technical and operational aspects. Technical aspects include system components, information technology services, information technology products, and mechanisms. Operational aspects include procedures (i.e., manually executed operations) and personnel (i.e., individuals operating technical controls and/or executing manual procedures). Organizational program protection plans can assist in identifying critical assets. If critical assets are resident within or supported by external service providers, organizations consider implementing CP-2(7) as a control enhancement.
Implementation Guidance
Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.
No engineering interpretation has been authored for CP-2 yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.
Assessment
Assessment Objectives
- personnel or roles to review a contingency plan is/are defined;
- personnel or roles to approve a contingency plan is/are defined;
- key contingency personnel (identified by name and/or by role) to whom copies of the contingency plan are distributed are defined;
- key contingency organizational elements to which copies of the contingency plan are distributed are defined;
- frequency of contingency plan review is defined;
- key contingency personnel (identified by name and/or by role) to communicate changes to are defined;
- key contingency organizational elements to communicate changes to are defined;
- a contingency plan for the system is developed that identifies essential mission and business functions and associated contingency requirements;
- a contingency plan for the system is developed that provides recovery objectives;
- a contingency plan for the system is developed that provides restoration priorities;
- a contingency plan for the system is developed that provides metrics;
- a contingency plan for the system is developed that addresses contingency roles;
- a contingency plan for the system is developed that addresses contingency responsibilities;
- a contingency plan for the system is developed that addresses assigned individuals with contact information;
- a contingency plan for the system is developed that addresses maintaining essential mission and business functions despite a system disruption, compromise, or failure;
- a contingency plan for the system is developed that addresses eventual, full-system restoration without deterioration of the controls originally planned and implemented;
- a contingency plan for the system is developed that addresses the sharing of contingency information;
- a contingency plan for the system is developed that is reviewed by <CP-02_ODP[01] personnel or roles>;
- a contingency plan for the system is developed that is approved by <CP-02_ODP[02] personnel or roles>;
- copies of the contingency plan are distributed to <CP-02_ODP[03] key contingency personnel>;
- copies of the contingency plan are distributed to <CP-02_ODP[04] organizational elements>;
- contingency planning activities are coordinated with incident handling activities;
- the contingency plan for the system is reviewed <CP-02_ODP[05] frequency>;
- the contingency plan is updated to address changes to the organization, system, or environment of operation;
- the contingency plan is updated to address problems encountered during contingency plan implementation, execution, or testing;
- contingency plan changes are communicated to <CP-02_ODP[06] key contingency personnel>;
- contingency plan changes are communicated to <CP-02_ODP[07] organizational elements>;
- lessons learned from contingency plan testing or actual contingency activities are incorporated into contingency testing;
- lessons learned from contingency plan training or actual contingency activities are incorporated into contingency testing and training;
- the contingency plan is protected from unauthorized disclosure;
- the contingency plan is protected from unauthorized modification.
Examine
[SELECT FROM: Contingency planning policy; procedures addressing contingency operations for the system; contingency plan; evidence of contingency plan reviews and updates; system security plan; other relevant documents or records].
Interview
[SELECT FROM: Organizational personnel with contingency planning and plan implementation responsibilities; organizational personnel with incident handling responsibilities; organizational personnel with knowledge of requirements for mission and business functions; organizational personnel with information security responsibilities].
Test
[SELECT FROM: Organizational processes for contingency plan development, review, update, and protection; mechanisms for developing, reviewing, updating, and/or protecting the contingency plan].
Overlays
STIGs & CCIs
No STIG checks or CCI mappings are currently loaded for CP-2. This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.
Learn more about STIG/CCI integration →Evidence
Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.
Policy
- Contingency planning policy
- contingency plan
- evidence of contingency plan reviews and updates
- system security plan
Testing
- Organizational processes for contingency plan development, review, update, and protection
- mechanisms for developing, reviewing, updating, and/or protecting the contingency plan
Other Records
- procedures addressing contingency operations for the system
- other relevant documents or records