{"data":{"id":"CP-02","name":"Contingency Plan","family":"CP","family_name":"Contingency Planning","withdrawn":false,"description":"a. Develop a contingency plan for the system that:\n1. Identifies essential mission and business functions and associated contingency requirements;\n2. Provides recovery objectives, restoration priorities, and metrics;\n3. Addresses contingency roles, responsibilities, assigned individuals with contact information;\n4. Addresses maintaining essential mission and business functions despite a system disruption, compromise, or failure;\n5. Addresses eventual, full system restoration without deterioration of the controls originally planned and implemented;\n6. Addresses the sharing of contingency information; and\n7. Is reviewed and approved by [Assignment: organization-defined personnel or roles];\nb. Distribute copies of the contingency plan to [Assignment: organization-defined key contingency personnel (identified by name and/or by role) and organizational elements];\nc. Coordinate contingency planning activities with incident handling activities;\nd. Review the contingency plan for the system [Assignment: organization-defined frequency];\ne. Update the contingency plan to address changes to the organization, system, or environment of operation and problems encountered during contingency plan implementation, execution, or testing;\nf. Communicate contingency plan changes to [Assignment: organization-defined key contingency personnel (identified by name and/or by role) and organizational elements];\ng. Incorporate lessons learned from contingency plan testing, training, or actual contingency activities into contingency testing and training; and\nh. Protect the contingency plan from unauthorized disclosure and modification.","supplemental_guidance":"Contingency planning for systems is part of an overall program for achieving continuity of operations for organizational mission and business functions. Contingency planning addresses system restoration and implementation of alternative mission or business processes when systems are compromised or breached. Contingency planning is considered throughout the system development life cycle and is a fundamental part of the system design. Systems can be designed for redundancy, to provide backup capabilities, and for resilience. Contingency plans reflect the degree of restoration required for organizational systems since not all systems need to fully recover to achieve the level of continuity of operations desired. System recovery objectives reflect applicable laws, executive orders, directives, regulations, policies, standards, guidelines, organizational risk tolerance, and system impact level.\n\nActions addressed in contingency plans include orderly system degradation, system shutdown, fallback to a manual mode, alternate information flows, and operating in modes reserved for when systems are under attack. By coordinating contingency planning with incident handling activities, organizations ensure that the necessary planning activities are in place and activated in the event of an incident. Organizations consider whether continuity of operations during an incident conflicts with the capability to automatically disable the system, as specified in IR-04(05). Incident response planning is part of contingency planning for organizations and is addressed in the IR (Incident Response) family.","enhancements":[{"id":"CP-02(01)","name":"Coordinate with Related Plans","statement":"Coordinate contingency plan development with organizational elements responsible for related plans.","baselines":["moderate","high"]},{"id":"CP-02(02)","name":"Capacity Planning","statement":"Conduct capacity planning so that necessary capacity for information processing, telecommunications, and environmental support exists during contingency operations.","baselines":["high"]},{"id":"CP-02(03)","name":"Resume Mission and Business Functions","statement":"Plan for the resumption of [Selection (one): all; essential] mission and business functions within [Assignment: organization-defined time period] of contingency plan activation.","baselines":["moderate","high"]},{"id":"CP-02(04)","name":"Resume All Mission and Business Functions","withdrawn":true,"incorporated_into":["CP-02(03)"]},{"id":"CP-02(05)","name":"Continue Mission and Business Functions","statement":"Plan for the continuance of [Selection (one): all; essential] mission and business functions with minimal or no loss of operational continuity and sustains that continuity until full system restoration at primary processing and/or storage sites.","baselines":["high"]},{"id":"CP-02(06)","name":"Alternate Processing and Storage Sites","statement":"Plan for the transfer of [Selection (one): all; essential] mission and business functions to alternate processing and/or storage sites with minimal or no loss of operational continuity and sustain that continuity through system restoration to primary processing and/or storage sites.","baselines":[]},{"id":"CP-02(07)","name":"Coordinate with External Service Providers","statement":"Coordinate the contingency plan with the contingency plans of external service providers to ensure that contingency requirements can be satisfied.","baselines":[]},{"id":"CP-02(08)","name":"Identify Critical Assets","statement":"Identify critical system assets supporting [Selection (one): all; essential] mission and business functions.","baselines":["moderate","high"]}],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"nist_800_53":{"rev5":{"id":"CP-02","name":"Contingency Plan","description":"a. Develop a contingency plan for the system that:\n1. Identifies essential mission and business functions and associated contingency requirements;\n2. Provides recovery objectives, restoration priorities, and metrics;\n3. Addresses contingency roles, responsibilities, assigned individuals with contact information;\n4. Addresses maintaining essential mission and business functions despite a system disruption, compromise, or failure;\n5. Addresses eventual, full system restoration without deterioration of the controls originally planned and implemented;\n6. Addresses the sharing of contingency information; and\n7. Is reviewed and approved by [Assignment: organization-defined personnel or roles];\nb. Distribute copies of the contingency plan to [Assignment: organization-defined key contingency personnel (identified by name and/or by role) and organizational elements];\nc. Coordinate contingency planning activities with incident handling activities;\nd. Review the contingency plan for the system [Assignment: organization-defined frequency];\ne. Update the contingency plan to address changes to the organization, system, or environment of operation and problems encountered during contingency plan implementation, execution, or testing;\nf. Communicate contingency plan changes to [Assignment: organization-defined key contingency personnel (identified by name and/or by role) and organizational elements];\ng. Incorporate lessons learned from contingency plan testing, training, or actual contingency activities into contingency testing and training; and\nh. Protect the contingency plan from unauthorized disclosure and modification.","discussion":"Contingency planning for systems is part of an overall program for achieving continuity of operations for organizational mission and business functions. Contingency planning addresses system restoration and implementation of alternative mission or business processes when systems are compromised or breached. Contingency planning is considered throughout the system development life cycle and is a fundamental part of the system design. Systems can be designed for redundancy, to provide backup capabilities, and for resilience. Contingency plans reflect the degree of restoration required for organizational systems since not all systems need to fully recover to achieve the level of continuity of operations desired. System recovery objectives reflect applicable laws, executive orders, directives, regulations, policies, standards, guidelines, organizational risk tolerance, and system impact level.\n\nActions addressed in contingency plans include orderly system degradation, system shutdown, fallback to a manual mode, alternate information flows, and operating in modes reserved for when systems are under attack. By coordinating contingency planning with incident handling activities, organizations ensure that the necessary planning activities are in place and activated in the event of an incident. Organizations consider whether continuity of operations during an incident conflicts with the capability to automatically disable the system, as specified in IR-04(05). Incident response planning is part of contingency planning for organizations and is addressed in the IR (Incident Response) family.","related_controls":["CP-03","CP-04","CP-06","CP-07","CP-08","CP-09","CP-10","CP-11","CP-13","IR-04","IR-06","IR-08","IR-09","MA-06","MP-02","MP-04","MP-05","PL-02","PM-08","PM-11","SA-15","SA-20","SC-07","SC-23","SI-12"],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"baseline_privacy":false,"new_in_rev5":false,"changes_from_rev4":"Develop and document a map of system data actions, addressing the sharing of contingency information and noting the system operations that process personally identifiable information; incorporate lessons learned into contingency planning tests and training"}},"compliance_mappings":{"iso_27001_2022":["7.5","A.5.2","A.5.29","A.5.30","A.8.6","A.8.14"],"iso_27002_2022":["5.29","5.30","8.6"],"cobit_2019":["BAI04","DSS04"],"pci_dss_v4":[],"nist_csf_2":["GV.OC-04","GV.OC-05","GV.SC-08","ID.AM-05","ID.IM-01","ID.IM-02","ID.IM-03","ID.IM-04","PR.IR-02","PR.IR-03","PR.IR-04","RC.CO-03","RC.CO-04","RC.RP-01","RC.RP-02","RC.RP-03"],"cis_controls_v8":["CIS 11.1"],"soc2_tsc":["A1.2","A1.2-POF1","A1.2-POF2","A1.2-POF3","CC7.4-POF5","CC7.5","CC9.1","CC9.1-POF1"],"finos_ccc":[],"iso_42001_2023":["A.4.5"],"iec_62443":["3-3 SR 7.2"],"asd_e8":[],"nis2":["Art. 21(2)(c)"],"apra_cps_234":[],"mas_trm":["8"],"pra_op_resilience":["SS1/21-3.1","SS1/21-4.1","SS1/21-5.1","SS1/21-8.1","SS1/21-10.1","SS2/21-10.1","SS2/21-12.1"],"bsi_grundschutz":["DER.4"],"anssi":["Hygiene.30","Hygiene.35","SecNumCloud.18.1"],"osfi_b13":["B-13.2.6"],"finma_circular":["IV.E(87)","IV.E(88)","IV.E(89)","IV.E(90)","IV.E(91)"],"gdpr":["Art.32(1)(b)","Art.32(1)(c)","Art.32(1)(d)"],"dora":["Art.11(1)","Art.11(3)","Art.11(4)","Art.12(1)"],"bio2":["5.29","5.30","8.6"],"rbi_csf":["Annex1.19","ITGRCA.28","ITGRCA.29"],"fisc":["FISC.O5"],"lgpd_bcb":["BCB.Art.3"],"hkma_tme1":["TME1.6.1","TME1.6.2"],"mlps_2":["8.1.10.11"],"dnb_good_practice":["DNB.8.3","DNB.11.1","DNB.11.4"],"cra":["CRA.I.2h"],"swift_cscf":[],"cbb_tm":["TM-14"],"cbuae":["CR-13"],"nca_ecc":["3-1","3-2","5-1"],"qatar_nia":["BC"],"uae_ia":["T12"],"bog_cisd":["CISD-BCM"],"bom_ctrm":["5.2"],"cbe_csf":["OVM-2"],"cbn_csf":["Part3.6","Part3.7"],"popia":["s19"],"sa_js2":["JS2-7.5"],"bcbs_239":["Principle 2","Principle 5","Principle 6"],"bot_cyber":["Ch4.2"],"cpmi_pfmi":["CG.RR","PFMI.P15","PFMI.P17"],"eba_ict":["3.5(a)","3.7.1","3.7.2","3.7.3","3.7.5"],"ecb_croe":["CROE.2.5.2","CROE.2.5.3"],"ffiec_is":["III.D"],"hipaa_sr":["§164.308(a)(7)(i)","§164.308(a)(7)(ii)(B)","§164.308(a)(7)(ii)(C)","§164.308(a)(7)(ii)(E)","§164.310(a)(2)(i)","§164.312(a)(2)(ii)"],"iosco_cyber":["PFMI-17","RR-2","RR-5"],"nydfs_500":["500.2","500.16"],"sebi_cscrf":["BCP-DR","CCMP","RC.CO","RC.IM","RC.RP"],"nerc_cip":["CIP-009-6"],"nrc_73_54":["RG5.71-B-CP"],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":["RESPONSE"],"api_1164":["Sec 11"],"awia":["Sec 2013(b)"],"iaea_nss":["Sec 8"],"pci_pts":[],"fips_140":[],"cbest":[],"tiber_eu":[],"pci_hsm":[],"common_criteria":[],"isae_3402":["Clause 4"],"fca_sysc_13":["SYSC 13.8.1","SYSC 13.8.2","SYSC 13.9.5"],"fda_21_cfr_11":[],"fda_cyber":["SA-6"],"hitrust_csf":["09.b","09.d","12.a","12.b"],"iso_27799":["9.2","17.1","17.2"],"lloyds_ms":["CRM.3","MS8.6","MS9.1"],"naic_ds":["4","4F-b"],"nhs_dspt":["NDG-7.1","NDG-7.2","NDG-7.4"],"pra_ss1_23":["P-IT.3"],"solvency_ii":["DR.266","DR.266-BCP","DR.274","EIOPA-Cloud-GL11","EIOPA-ICT-4.10"],"owasp_masvs_v2":[],"csa_ccm_v4":["BCR-01","BCR-02","BCR-03","BCR-04","BCR-05","BCR-07","BCR-09","IVS-02"],"csa_aicm":["BCR-01","BCR-02","BCR-03","BCR-04","BCR-05","BCR-07","BCR-09","I&S-02"],"ccss_v9":["1.06.1","1.06.4"],"mica":["Art.47(1)","Art.62(6)","Art.68(5)"],"basel_sco60":["SCO60.21","SCO60.23","SCO60.50","SCO60.53","SCO60.63"],"bssc":["GSP-06","NOS-07"],"sec_custody_digital":["SEC-CD-12"],"dpdpa":["Rules.6(1)(d)"]},"attack_techniques":[{"id":"T1485","name":"Data Destruction","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Contingency plans that define roles, responsibilities, and procedures for data destruction scenarios enable coordinated organizational response—including backup activation, forensic preservation, and service restoration—to minimize impact."},{"id":"T1486","name":"Data Encrypted for Impact","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Contingency planning for ransomware scenarios—including decision frameworks for ransom payment, backup restoration priorities, and communication protocols—enables structured organizational response to encryption-based extortion attacks."},{"id":"T1490","name":"Inhibit System Recovery","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Contingency plans that account for adversary attempts to inhibit recovery—including procedures for alternative backup access, manual system restoration, and vendor engagement—ensure recovery capability even when primary mechanisms fail."},{"id":"T1491","name":"Defacement","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Contingency planning for defacement incidents—including pre-staged content, communication templates, and restoration procedures—enables rapid organizational response that minimizes reputational damage from public-facing defacement."},{"id":"T1561","name":"Disk Wipe","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Contingency plans addressing total system loss through disk wipe scenarios—including hardware procurement procedures, system rebuild priorities, and data restoration sequences—enable structured recovery from destructive attacks."},{"id":"T1491.001","name":"Internal Defacement","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Contingency plans for internal defacement—including procedures for content restoration, employee communication, and internal service recovery—enable coordinated response when adversaries target internal-facing applications."},{"id":"T1491.002","name":"External Defacement","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Contingency planning for external defacement—including public communication protocols, customer notification procedures, and web content restoration priorities—enables rapid response to protect organizational reputation."},{"id":"T1561.001","name":"Disk Content Wipe","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Contingency plans addressing disk content wipe scenarios—including bare-metal restore procedures, system priority rankings, and recovery time objectives—enable structured system reconstitution after destructive attacks."},{"id":"T1561.002","name":"Disk Structure Wipe","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Contingency planning for disk structure wipe attacks—including hardware replacement procedures, partition recovery techniques, and system rebuild sequences—ensures recovery capability from the most destructive disk attacks."}],"metadata":{"last_reviewed":"2026-10-03","review_notes":"2026-10-03: iso_27001_2022 7.5, A.5.2, A.8.14 added from NIST's SP 800-53 Rev 5 to ISO/IEC 27001:2022 crosswalk (OLIR entry 155), which OSA's mapping now takes as its base. 2026-10-03: nist_csf_2 ID.IM-01, ID.IM-02, ID.IM-03, PR.IR-02, RC.CO-04, RC.RP-03 added from NIST's CSF 2.0 to SP 800-53 Rev 5.2.0 crosswalk (OLIR entry 186), which OSA's mapping now takes as its base.","mapping_status":"complete"},"function":"preventative","used_by_patterns":["SP-008","SP-019","SP-023","SP-033","SP-034","SP-040","SP-042","SP-051"]}}