Skip to main content

πŸ’Ό CP-2 CONTINGENCY PLAN

  • Contextual name: πŸ’Ό CP-2 CONTINGENCY PLAN
  • ID: /frameworks/nist-sp-800-53-r4/cp/02
  • Located in: πŸ’Ό CP CONTINGENCY PLANNING

Description​

The organization: CP-2a. Develops a contingency plan for the information system that: CP-2a.1. Identifies essential missions and business functions and associated contingency requirements; CP-2a.2. Provides recovery objectives, restoration priorities, and metrics; CP-2a.3. Addresses contingency roles, responsibilities, assigned individuals with contact information; CP-2a.4. Addresses maintaining essential missions and business functions despite an information system disruption, compromise, or failure; CP-2a.5. Addresses eventual, full information system restoration without deterioration of the security safeguards originally planned and implemented; and CP-2a.6. Is reviewed and approved by [Assignment: organization-defined personnel or roles]; CP-2b. Distributes copies of the contingency plan to [Assignment: organization-defined key contingency personnel (identified by name and/or by role) and organizational elements]; CP-2c. Coordinates contingency planning activities with incident handling activities; CP-2d. Reviews the contingency plan for the information system [Assignment: organization-defined frequency]; CP-2e. Updates the contingency plan to address changes to the organization, information system, or environment of operation and problems encountered during contingency plan implementation, execution, or testing; CP-2f. Communicates contingency plan changes to [Assignment: organization-defined key contingency personnel (identified by name and/or by role) and organizational elements]; and CP-2g. Protects the contingency plan from unauthorized disclosure and modification.

Similar​

  • Internal
    • ID: dec-c-36fb093d

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό DE.AE-4: Impact of events is determined1414
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό ID.AM-5: Resources (e.g., hardware, devices, data, time, personnel, and software) are prioritized based on their classification, criticality, and business value
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό ID.AM-6: Cybersecurity roles and responsibilities for the entire workforce and third-party stakeholders (e.g., suppliers, customers, partners) are established
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό ID.BE-1: The organization's role in the supply chain is identified and communicated
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό ID.BE-5: Resilience requirements to support delivery of critical services are established for all operating states (e.g. under duress/attack, during recovery, normal operations)44
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό ID.SC-5: Response and recovery planning and testing are conducted with suppliers and third-party providers11
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό PR.DS-4: Adequate capacity to ensure availability is maintained11
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό PR.IP-7: Protection processes are improved2
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό PR.IP-9: Response plans (Incident Response and Business Continuity) and recovery plans (Incident Recovery and Disaster Recovery) are in place and managed33
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό RC.CO-3: Recovery activities are communicated to internal and external stakeholders as well as executive and management teams
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό RC.IM-1: Recovery plans incorporate lessons learned
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό RC.IM-2: Recovery strategies are updated
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό RS.AN-2: The impact of the incident is understood
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό RS.AN-4: Incidents are categorized consistent with response plans
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό RS.CO-1: Personnel know their roles and order of operations when a response is needed
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό RS.CO-3: Information is shared consistent with response plans1617
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό RS.CO-4: Coordination with stakeholders occurs consistent with response plans
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό RS.IM-1: Response plans incorporate lessons learned
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό RS.IM-2: Response strategies are updated
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό RS.RP-1: Response plan is executed during or after an incident

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό CP-2 (1) COORDINATE WITH RELATED PLANS
πŸ’Ό CP-2 (2) CAPACITY PLANNING
πŸ’Ό CP-2 (3) RESUME ESSENTIAL MISSIONS _ BUSINESS FUNCTIONS
πŸ’Ό CP-2 (4) RESUME ALL MISSIONS _ BUSINESS FUNCTIONS
πŸ’Ό CP-2 (5) CONTINUE ESSENTIAL MISSIONS _ BUSINESS FUNCTIONS
πŸ’Ό CP-2 (6) ALTERNATE PROCESSING _ STORAGE SITE
πŸ’Ό CP-2 (7) COORDINATE WITH EXTERNAL SERVICE PROVIDERS
πŸ’Ό CP-2 (8) IDENTIFY CRITICAL ASSETS