Contingency Plan

✓ LOW ✓ MODERATE ✓ HIGH
7 Enhancements 1 Overlay 25 Related Controls
Graph
Export ▾

Requirements NIST SOURCE

    1. 1.Identifies essential mission and business functions and associated contingency requirements;
    2. 2.Provides recovery objectives, restoration priorities, and metrics;
    3. 3.Addresses contingency roles, responsibilities, assigned individuals with contact information;
    4. 4.Addresses maintaining essential mission and business functions despite a system disruption, compromise, or failure;
    5. 5.Addresses eventual, full system restoration without deterioration of the controls originally planned and implemented;
    6. 6.Addresses the sharing of contingency information; and
    7. 7.Is reviewed and approved by [organization-defined personnel or roles];
Discussion (NIST Supplemental Guidance)

Contingency planning for systems is part of an overall program for achieving continuity of operations for organizational mission and business functions. Contingency planning addresses system restoration and implementation of alternative mission or business processes when systems are compromised or breached. Contingency planning is considered throughout the system development life cycle and is a fundamental part of the system design. Systems can be designed for redundancy, to provide backup capabilities, and for resilience. Contingency plans reflect the degree of restoration required for organizational systems since not all systems need to fully recover to achieve the level of continuity of operations desired. System recovery objectives reflect applicable laws, executive orders, directives, regulations, policies, standards, guidelines, organizational risk tolerance, and system impact level. Actions addressed in contingency plans include orderly system degradation, system shutdown, fallback to a manual mode, alternate information flows, and operating in modes reserved for when systems are under attack. By coordinating contingency planning with incident handling activities, organizations ensure that the necessary planning activities are in place and activated in the event of an incident. Organizations consider whether continuity of operations during an incident conflicts with the capability to automatically disable the system, as specified in IR-4(5) . Incident response planning is part of contingency planning for organizations and is addressed in the IR (Incident Response) family.

Enhancements NIST SOURCE

CP-2(1) Coordinate with Related Plans LOW ✓ MODERATE ✓ HIGH

Coordinate contingency plan development with organizational elements responsible for related plans.

Discussion

Plans that are related to contingency plans include Business Continuity Plans, Disaster Recovery Plans, Critical Infrastructure Plans, Continuity of Operations Plans, Crisis Communications Plans, Insider Threat Implementation Plans, Data Breach Response Plans, Cyber Incident Response Plans, Breach Response Plans, and Occupant Emergency Plans.

Open full page for CP-2(1) →
CP-2(2) Capacity Planning LOW MODERATE ✓ HIGH

Conduct capacity planning so that necessary capacity for information processing, telecommunications, and environmental support exists during contingency operations.

Discussion

Capacity planning is needed because different threats can result in a reduction of the available processing, telecommunications, and support services intended to support essential mission and business functions. Organizations anticipate degraded operations during contingency operations and factor the degradation into capacity planning. For capacity planning, environmental support refers to any environmental factor for which the organization determines that it needs to provide support in a contingency situation, even if in a degraded state. Such determinations are based on an organizational assessment of risk, system categorization (impact level), and organizational risk tolerance.

Open full page for CP-2(2) →
CP-2(3) Resume Mission and Business Functions LOW ✓ MODERATE ✓ HIGH

Plan for the resumption of [one of: all; essential] mission and business functions within [time period] of contingency plan activation.

Discussion

Organizations may choose to conduct contingency planning activities to resume mission and business functions as part of business continuity planning or as part of business impact analyses. Organizations prioritize the resumption of mission and business functions. The time period for resuming mission and business functions may be dependent on the severity and extent of the disruptions to the system and its supporting infrastructure.

Open full page for CP-2(3) →
CP-2(4) Resume All Mission and Business Functions WITHDRAWN

Withdrawn. Incorporated into CP-2(3).

CP-2(5) Continue Mission and Business Functions LOW MODERATE ✓ HIGH

Plan for the continuance of [one of: all; essential] mission and business functions with minimal or no loss of operational continuity and sustains that continuity until full system restoration at primary processing and/or storage sites.

Discussion

Organizations may choose to conduct the contingency planning activities to continue mission and business functions as part of business continuity planning or business impact analyses. Primary processing and/or storage sites defined by organizations as part of contingency planning may change depending on the circumstances associated with the contingency.

Open full page for CP-2(5) →
CP-2(6) Alternate Processing and Storage Sites LOW MODERATE HIGH

Plan for the transfer of [one of: all; essential] mission and business functions to alternate processing and/or storage sites with minimal or no loss of operational continuity and sustain that continuity through system restoration to primary processing and/or storage sites.

Discussion

Organizations may choose to conduct contingency planning activities for alternate processing and storage sites as part of business continuity planning or business impact analyses. Primary processing and/or storage sites defined by organizations as part of contingency planning may change depending on the circumstances associated with the contingency.

Open full page for CP-2(6) →
CP-2(7) Coordinate with External Service Providers LOW MODERATE HIGH

Coordinate the contingency plan with the contingency plans of external service providers to ensure that contingency requirements can be satisfied.

Discussion

When the capability of an organization to carry out its mission and business functions is dependent on external service providers, developing a comprehensive and timely contingency plan may become more challenging. When mission and business functions are dependent on external service providers, organizations coordinate contingency planning activities with the external entities to ensure that the individual plans reflect the overall contingency needs of the organization.

Open full page for CP-2(7) →
CP-2(8) Identify Critical Assets LOW ✓ MODERATE ✓ HIGH

Identify critical system assets supporting [one of: all; essential] mission and business functions.

Discussion

Organizations may choose to identify critical assets as part of criticality analysis, business continuity planning, or business impact analyses. Organizations identify critical system assets so that additional controls can be employed (beyond the controls routinely implemented) to help ensure that organizational mission and business functions can continue to be conducted during contingency operations. The identification of critical information assets also facilitates the prioritization of organizational resources. Critical system assets include technical and operational aspects. Technical aspects include system components, information technology services, information technology products, and mechanisms. Operational aspects include procedures (i.e., manually executed operations) and personnel (i.e., individuals operating technical controls and/or executing manual procedures). Organizational program protection plans can assist in identifying critical assets. If critical assets are resident within or supported by external service providers, organizations consider implementing CP-2(7) as a control enhancement.

Open full page for CP-2(8) →

Implementation Guidance

Engineering Interpretation

Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.

No engineering interpretation has been authored for CP-2 yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.

Assessment

NIST SP 800-53A REV 5.2.0

Assessment Objectives

  1. personnel or roles to review a contingency plan is/are defined;
  2. personnel or roles to approve a contingency plan is/are defined;
  3. key contingency personnel (identified by name and/or by role) to whom copies of the contingency plan are distributed are defined;
  4. key contingency organizational elements to which copies of the contingency plan are distributed are defined;
  5. frequency of contingency plan review is defined;
  6. key contingency personnel (identified by name and/or by role) to communicate changes to are defined;
  7. key contingency organizational elements to communicate changes to are defined;
  8. a contingency plan for the system is developed that identifies essential mission and business functions and associated contingency requirements;
  9. a contingency plan for the system is developed that provides recovery objectives;
  10. a contingency plan for the system is developed that provides restoration priorities;
  11. a contingency plan for the system is developed that provides metrics;
  12. a contingency plan for the system is developed that addresses contingency roles;
  13. a contingency plan for the system is developed that addresses contingency responsibilities;
  14. a contingency plan for the system is developed that addresses assigned individuals with contact information;
  15. a contingency plan for the system is developed that addresses maintaining essential mission and business functions despite a system disruption, compromise, or failure;
  16. a contingency plan for the system is developed that addresses eventual, full-system restoration without deterioration of the controls originally planned and implemented;
  17. a contingency plan for the system is developed that addresses the sharing of contingency information;
  18. a contingency plan for the system is developed that is reviewed by <CP-02_ODP[01] personnel or roles>;
  19. a contingency plan for the system is developed that is approved by <CP-02_ODP[02] personnel or roles>;
  20. copies of the contingency plan are distributed to <CP-02_ODP[03] key contingency personnel>;
  21. copies of the contingency plan are distributed to <CP-02_ODP[04] organizational elements>;
  22. contingency planning activities are coordinated with incident handling activities;
  23. the contingency plan for the system is reviewed <CP-02_ODP[05] frequency>;
  24. the contingency plan is updated to address changes to the organization, system, or environment of operation;
  25. the contingency plan is updated to address problems encountered during contingency plan implementation, execution, or testing;
  26. contingency plan changes are communicated to <CP-02_ODP[06] key contingency personnel>;
  27. contingency plan changes are communicated to <CP-02_ODP[07] organizational elements>;
  28. lessons learned from contingency plan testing or actual contingency activities are incorporated into contingency testing;
  29. lessons learned from contingency plan training or actual contingency activities are incorporated into contingency testing and training;
  30. the contingency plan is protected from unauthorized disclosure;
  31. the contingency plan is protected from unauthorized modification.

Examine

[SELECT FROM: Contingency planning policy; procedures addressing contingency operations for the system; contingency plan; evidence of contingency plan reviews and updates; system security plan; other relevant documents or records].

Interview

[SELECT FROM: Organizational personnel with contingency planning and plan implementation responsibilities; organizational personnel with incident handling responsibilities; organizational personnel with knowledge of requirements for mission and business functions; organizational personnel with information security responsibilities].

Test

[SELECT FROM: Organizational processes for contingency plan development, review, update, and protection; mechanisms for developing, reviewing, updating, and/or protecting the contingency plan].

Overlays

OT/ICS Overlay SP 800-82r3

NIST SP 800-82r3 Appendix F, Table 22. Blank baseline means the control/control enhancement is not selected in that initial OT baseline.

LOW

  • Base control: Included (matches standard baseline)

MODERATE

  • Base control: Included (matches standard baseline)
  • Included: (1) (3) (8)

HIGH

  • Base control: Included (matches standard baseline)
  • Included: (1) (2) (3) (5) (8)

STIGs & CCIs

No STIG checks or CCI mappings are currently loaded for CP-2. This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.

Learn more about STIG/CCI integration →

Evidence

Potential Evidence — Derived

Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.

Policy

  • Contingency planning policy
  • contingency plan
  • evidence of contingency plan reviews and updates
  • system security plan

Testing

  • Organizational processes for contingency plan development, review, update, and protection
  • mechanisms for developing, reviewing, updating, and/or protecting the contingency plan

Other Records

  • procedures addressing contingency operations for the system
  • other relevant documents or records