Skip to main content

πŸ’Ό CP-2 Contingency Plan (L)(M)(H)

  • Contextual name: πŸ’Ό CP-2 Contingency Plan (L)(M)(H)
  • ID: /frameworks/fedramp-low-security-controls/cp/02
  • Located in: πŸ’Ό Contingency Planning

Description​

a. Develop a contingency plan for the system that:

  1. Identifies essential mission and business functions and associated contingency requirements;

  2. Provides recovery objectives, restoration priorities, and metrics;

  3. Addresses contingency roles, responsibilities, assigned individuals with contact information;

  4. Addresses maintaining essential mission and business functions despite a system disruption, compromise, or failure;

  5. Addresses eventual, full system restoration without deterioration of the controls originally planned and implemented;

  6. Addresses the sharing of contingency information; and

  7. Is reviewed and approved by [Assignment: organization-defined personnel or roles];

b. Distribute copies of the contingency plan to [Assignment: organization-defined key contingency personnel (identified by name and/or by role) and organizational elements];

c. Coordinate contingency planning activities with incident handling activities;

d. Review the contingency plan for the system [FedRAMP Assignment: at least annually];

e. Update the contingency plan to address changes to the organization, system, or environment of operation and problems encountered during contingency plan implementation, execution, or testing;

f. Communicate contingency plan changes to [Assignment: organization-defined key contingency personnel (identified by name and/or by role) and organizational elements];

g. Incorporate lessons learned from contingency plan testing, training, or actual contingency activities into contingency testing and training; and

h. Protect the contingency plan from unauthorized disclosure and modification.

CP-2 Additional FedRAMP Requirements and Guidance:

Requirement: For JAB authorizations the contingency lists include designated FedRAMP personnel.

Requirement: CSPs must use the FedRAMP Information System Contingency Plan (ISCP) Template (available on the fedramp.gov: https://www.fedramp.gov/assets/resources/templates/SSP-Appendix-G-Information-System-Contingency-Plan-(ISCP)-Template.docx).

Similar​

  • Sections
    • /frameworks/nist-sp-800-53-r5/cp/02
    • /frameworks/fedramp-high-security-controls/cp/02
  • Internal
    • ID: dec-c-ec2b11b8

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό FedRAMP High Security Controls β†’ πŸ’Ό CP-2 Contingency Plan (L)(M)(H)51
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό CP-2 Contingency Plan81

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags