{"data":{"id":"CP-12","name":"Safe Mode","family":"CP","family_name":"Contingency Planning","withdrawn":false,"description":"When [Assignment: organization-defined conditions] are detected, enter a safe mode of operation with [Assignment: organization-defined restrictions of safe mode of operation].","supplemental_guidance":"For systems that support critical mission and business functions—including military operations, civilian space operations, nuclear power plant operations, and air traffic control operations (especially real-time operational environments)—organizations can identify certain conditions under which those systems revert to a predefined safe mode of operation. The safe mode of operation, which can be activated either automatically or manually, restricts the operations that systems can execute when those conditions are encountered. Restriction includes allowing only selected functions to execute that can be carried out under limited power or with reduced communications bandwidth.","enhancements":[],"baseline_low":false,"baseline_moderate":false,"baseline_high":false,"nist_800_53":{"rev5":{"id":"CP-12","name":"Safe Mode","description":"When [Assignment: organization-defined conditions] are detected, enter a safe mode of operation with [Assignment: organization-defined restrictions of safe mode of operation].","discussion":"For systems that support critical mission and business functions—including military operations, civilian space operations, nuclear power plant operations, and air traffic control operations (especially real-time operational environments)—organizations can identify certain conditions under which those systems revert to a predefined safe mode of operation. The safe mode of operation, which can be activated either automatically or manually, restricts the operations that systems can execute when those conditions are encountered. Restriction includes allowing only selected functions to execute that can be carried out under limited power or with reduced communications bandwidth.","related_controls":["CM-02","SA-08","SC-24","SI-13","SI-17"],"baseline_low":false,"baseline_moderate":false,"baseline_high":false,"baseline_privacy":false,"new_in_rev5":false,"changes_from_rev4":"No significant changes from Rev 4."}},"compliance_mappings":{"iso_27001_2022":[],"iso_27002_2022":["5.29"],"cobit_2019":["DSS04"],"pci_dss_v4":[],"nist_csf_2":[],"cis_controls_v8":[],"soc2_tsc":[],"finos_ccc":[],"iso_42001_2023":[],"iec_62443":[],"asd_e8":[],"nis2":[],"apra_cps_234":[],"mas_trm":["8"],"pra_op_resilience":[],"bsi_grundschutz":["DER.4"],"anssi":[],"osfi_b13":[],"finma_circular":[],"gdpr":[],"dora":["Art.11(1)"],"bio2":["5.29"],"rbi_csf":["ITGRCA.28"],"fisc":[],"lgpd_bcb":[],"hkma_tme1":[],"mlps_2":[],"dnb_good_practice":[],"cra":[],"swift_cscf":[],"cbb_tm":["TM-14"],"cbuae":["CR-13"],"nca_ecc":["3-1"],"qatar_nia":["BC"],"uae_ia":["T12"],"bog_cisd":["CISD-BCM"],"bom_ctrm":["5.2"],"cbe_csf":["OVM-2"],"cbn_csf":["Part3.7"],"sa_js2":["JS2-7.5"],"bot_cyber":["Ch4.2"],"cpmi_pfmi":["CG.RR"],"eba_ict":["3.7.2"],"ecb_croe":["CROE.2.5.2","CROE.2.5.3"],"hipaa_sr":["§164.308(a)(7)(ii)(C)"],"iosco_cyber":["PFMI-17","RR-2"],"sebi_cscrf":["RC.RP"],"nerc_cip":[],"nrc_73_54":[],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":[],"api_1164":[],"awia":[],"iaea_nss":[],"pci_pts":[],"fips_140":[],"cbest":[],"tiber_eu":[],"pci_hsm":[],"common_criteria":["CC Part 2 — FPT"],"isae_3402":[],"fca_sysc_13":["SYSC 13.8.1"],"fda_21_cfr_11":[],"fda_cyber":["SA-6"],"hitrust_csf":[],"iso_27799":["17.2"],"lloyds_ms":["MS8.6"],"naic_ds":[],"nhs_dspt":["NDG-7.4"],"pra_ss1_23":[],"solvency_ii":["DR.266-BCP","EIOPA-ICT-4.10"],"owasp_masvs_v2":[],"csa_ccm_v4":[],"csa_aicm":[],"ccss_v9":[],"mica":[],"basel_sco60":[],"bssc":[],"sec_custody_digital":[],"dpdpa":[]},"attack_techniques":[],"metadata":{"last_reviewed":"2026-02-19","review_notes":"Generated from NIST SP 800-53 Rev 5 with compliance mappings from framework-coverage data","mapping_status":"complete"},"function":"corrective","used_by_patterns":[]}}