id: "CP-02" title: "Contingency Plan" family: "CP" family_name: "Contingency Planning" sort_id: "cp-02" priority: "P2" implementation_level: "organization" enhancements: - cp-2.1 - cp-2.2 - cp-2.3 - cp-2.4 - cp-2.5 - cp-2.6 - cp-2.7 - cp-2.8
Develop a contingency plan for the system that:
Identifies essential mission and business functions and associated contingency requirements;
Provides recovery objectives, restoration priorities, and metrics;
Addresses contingency roles, responsibilities, assigned individuals with contact information;
Addresses maintaining essential mission and business functions despite a system disruption, compromise, or failure;
Addresses eventual, full system restoration without deterioration of the controls originally planned and implemented;
Addresses the sharing of contingency information; and
Is reviewed and approved by {{ insert: param, cp-2_prm_1 }};
Distribute copies of the contingency plan to {{ insert: param, cp-2_prm_2 }};
Coordinate contingency planning activities with incident handling activities;
Review the contingency plan for the system {{ insert: param, cp-02_odp.05 }};
Update the contingency plan to address changes to the organization, system, or environment of operation and problems encountered during contingency plan implementation, execution, or testing;
Communicate contingency plan changes to {{ insert: param, cp-2_prm_4 }};
Incorporate lessons learned from contingency plan testing, training, or actual contingency activities into contingency testing and training; and
Protect the contingency plan from unauthorized disclosure and modification.
Guidance
Contingency planning for systems is part of an overall program for achieving continuity of operations for organizational mission and business functions. Contingency planning addresses system restoration and implementation of alternative mission or business processes when systems are compromised or breached. Contingency planning is considered throughout the system development life cycle and is a fundamental part of the system design. Systems can be designed for redundancy, to provide backup capabilities, and for resilience. Contingency plans reflect the degree of restoration required for organizational systems since not all systems need to fully recover to achieve the level of continuity of operations desired. System recovery objectives reflect applicable laws, executive orders, directives, regulations, policies, standards, guidelines, organizational risk tolerance, and system impact level.
Actions addressed in contingency plans include orderly system degradation, system shutdown, fallback to a manual mode, alternate information flows, and operating in modes reserved for when systems are under attack. By coordinating contingency planning with incident handling activities, organizations ensure that the necessary planning activities are in place and activated in the event of an incident. Organizations consider whether continuity of operations during an incident conflicts with the capability to automatically disable the system, as specified in IR-4(5) . Incident response planning is part of contingency planning for organizations and is addressed in the IR (Incident Response) family.
Assessment Objective: a contingency plan for the system is developed that identifies essential mission and business functions and associated contingency requirements;
Assessment Objective: a contingency plan for the system is developed that provides recovery objectives;
Assessment Objective: a contingency plan for the system is developed that provides restoration priorities;
Assessment Objective: a contingency plan for the system is developed that provides metrics;
Assessment Objective: a contingency plan for the system is developed that addresses contingency roles;
Assessment Objective: a contingency plan for the system is developed that addresses contingency responsibilities;
Assessment Objective: a contingency plan for the system is developed that addresses assigned individuals with contact information;
Assessment Objective: a contingency plan for the system is developed that addresses maintaining essential mission and business functions despite a system disruption, compromise, or failure;
Assessment Objective: a contingency plan for the system is developed that addresses eventual, full-system restoration without deterioration of the controls originally planned and implemented;
Assessment Objective: a contingency plan for the system is developed that addresses the sharing of contingency information;
Assessment Objective: a contingency plan for the system is developed that is reviewed by {{ insert: param, cp-02_odp.01 }};
Assessment Objective: a contingency plan for the system is developed that is approved by {{ insert: param, cp-02_odp.02 }};
Assessment Objective: copies of the contingency plan are distributed to {{ insert: param, cp-02_odp.03 }};
Assessment Objective: copies of the contingency plan are distributed to {{ insert: param, cp-02_odp.04 }};
Assessment Objective: contingency planning activities are coordinated with incident handling activities;
Assessment Objective: the contingency plan for the system is reviewed {{ insert: param, cp-02_odp.05 }};
Assessment Objective: the contingency plan is updated to address changes to the organization, system, or environment of operation;
Assessment Objective: the contingency plan is updated to address problems encountered during contingency plan implementation, execution, or testing;
Assessment Objective: contingency plan changes are communicated to {{ insert: param, cp-02_odp.06 }};
Assessment Objective: contingency plan changes are communicated to {{ insert: param, cp-02_odp.07 }};
Assessment Objective: lessons learned from contingency plan testing or actual contingency activities are incorporated into contingency testing;
Assessment Objective: lessons learned from contingency plan training or actual contingency activities are incorporated into contingency testing and training;
Assessment Objective: the contingency plan is protected from unauthorized disclosure;
Assessment Objective: the contingency plan is protected from unauthorized modification.
Contingency planning policy
procedures addressing contingency operations for the system
contingency plan
evidence of contingency plan reviews and updates
system security plan
other relevant documents or records
Organizational personnel with contingency planning and plan implementation responsibilities
organizational personnel with incident handling responsibilities
organizational personnel with knowledge of requirements for mission and business functions
organizational personnel with information security responsibilities
Organizational processes for contingency plan development, review, update, and protection
mechanisms for developing, reviewing, updating, and/or protecting the contingency plan