# CP-02 Contingency Plan

NIST SP 800-53 control. Family: CP Contingency Planning. Function: preventative. Baselines: low, moderate, high. Mapping licence: CC BY-SA 4.0.

Statement: a. Develop a contingency plan for the system that: 1. Identifies essential mission and business functions and associated contingency requirements; 2. Provides recovery objectives, restoration priorities, and metrics; 3. Addresses contingency roles, responsibilities, assigned individuals with contact information; 4. Addresses maintaining essential mission and business functions despite a system disruption, compromise, or failure; 5. Addresses eventual, full system restoration without deterioration of the controls originally planned and implemented; 6. Addresses the sharing of contingency information; and 7. Is reviewed and approved by [Assignment: organization-defined personnel or roles]; b. Distribute copies of the contingency plan to [Assignment: organization-defined key contingency personnel (identified by name and/or by role) and organizational elements]; c. Coordinate contingency planning activities with incident handling activities; d. Review the contingency plan for the system [Assignment: organization-defined frequency]; e. Update the contingency plan to address changes to the organization, system, or environment of operation and problems encountered during contingency plan implementation, execution, or testing; f. Communicate contingency plan changes to [Assignment: organization-defined key contingency personnel (identified by name and/or by role) and organizational elements]; g. Incorporate lessons learned from contingency plan testing, training, or actual contingency activities into contingency testing and training; and h. Protect the contingency plan from unauthorized disclosure and modification.
Guidance: Contingency planning for systems is part of an overall program for achieving continuity of operations for organizational mission and business functions. Contingency planning addresses system restoration and implementation of alternative mission or business processes when systems are compromised or breached. Contingency planning is considered throughout the system development life cycle and is a fundamental part of the system design. Systems can be designed for redundancy, to provide backup capabilities, and for resilience. Contingency plans reflect the degree of restoration required for organizational systems since not all systems need to fully recover to achieve the level of continuity of operations desired. System recovery objectives reflect applicable laws, executive orders, directives, regulations, policies, standards, guidelines, organizational risk tolerance, and system impact level. Actions addressed in contingency plans include orderly system degradation, system shutdown, fallback to a manual mode, alternate information flows, and operating in modes reserved for when systems are under attack. By coordinating contingency planning with incident handling activities, organizations ensure that the necessary planning activities are in place and activated in the event of an incident. Organizations consider whether continuity of operations during an incident conflicts with the capability to automatically disable the system, as specified in IR-04(05). Incident response planning is part of contingency planning for organizations and is addressed in the IR (Incident Response) family.

## Enhancements (7)
- CP-02(01) Coordinate with Related Plans. Baselines: moderate, high
- CP-02(02) Capacity Planning. Baselines: high
- CP-02(03) Resume Mission and Business Functions. Baselines: moderate, high
- CP-02(05) Continue Mission and Business Functions. Baselines: high
- CP-02(06) Alternate Processing and Storage Sites
- CP-02(07) Coordinate with External Service Providers
- CP-02(08) Identify Critical Assets. Baselines: moderate, high
Withdrawn by NIST: CP-02(04) (now in CP-02(03)).
Each enhancement's statement: /api/v1/controls/CP-02?fields=enhancements

## Patterns that use it (8)
- Critical (1): SP-034 Cyber Resilience
- Important (5): SP-008 Public Web Server Pattern; SP-023 Industrial Control Systems; SP-033 Passkey Authentication; SP-040 Post-Quantum Cryptography and Quantum Readiness; SP-042 Third Party Risk Management
- Standard (2): SP-019 Secure Ad-Hoc File Exchange Pattern; SP-051 Tokenised Asset Security Architecture (draft)

## Clauses by framework (70 frameworks)
- iso_27001_2022: 7.5, A.5.2, A.5.29, A.5.30, A.8.6, A.8.14. OSA's own, not in NIST's crosswalk: A.5.30, A.8.6
- iso_27002_2022: 5.29, 5.30, 8.6
- cobit_2019: BAI04, DSS04
- nist_csf_2: GV.OC-04, GV.OC-05, GV.SC-08, ID.AM-05, ID.IM-01, ID.IM-02, ID.IM-03, ID.IM-04, PR.IR-02, PR.IR-03, PR.IR-04, RC.CO-03, RC.CO-04, RC.RP-01, RC.RP-02, RC.RP-03. OSA's own, not in NIST's crosswalk: GV.OC-04, GV.OC-05, GV.SC-08, ID.AM-05, PR.IR-03, PR.IR-04, RC.CO-03, RC.RP-01, RC.RP-02
- cis_controls_v8: CIS 11.1
- soc2_tsc: A1.2, A1.2-POF1, A1.2-POF2, A1.2-POF3, CC7.4-POF5, CC7.5, CC9.1, CC9.1-POF1
- iso_42001_2023: A.4.5
- iec_62443: 3-3 SR 7.2
- nis2: Art. 21(2)(c)
- mas_trm: 8
- pra_op_resilience: SS1/21-3.1, SS1/21-4.1, SS1/21-5.1, SS1/21-8.1, SS1/21-10.1, SS2/21-10.1, SS2/21-12.1
- bsi_grundschutz: DER.4
- anssi: Hygiene.30, Hygiene.35, SecNumCloud.18.1
- osfi_b13: B-13.2.6
- finma_circular: IV.E(87), IV.E(88), IV.E(89), IV.E(90), IV.E(91)
- gdpr: Art.32(1)(b), Art.32(1)(c), Art.32(1)(d)
- dora: Art.11(1), Art.11(3), Art.11(4), Art.12(1)
- bio2: 5.29, 5.30, 8.6
- rbi_csf: Annex1.19, ITGRCA.28, ITGRCA.29
- fisc: FISC.O5
- lgpd_bcb: BCB.Art.3
- hkma_tme1: TME1.6.1, TME1.6.2
- mlps_2: 8.1.10.11
- dnb_good_practice: DNB.8.3, DNB.11.1, DNB.11.4
- cra: CRA.I.2h
- cbb_tm: TM-14
- cbuae: CR-13
- nca_ecc: 3-1, 3-2, 5-1
- qatar_nia: BC
- uae_ia: T12
- bog_cisd: CISD-BCM
- bom_ctrm: 5.2
- cbe_csf: OVM-2
- cbn_csf: Part3.6, Part3.7
- popia: s19
- sa_js2: JS2-7.5
- bcbs_239: Principle 2, Principle 5, Principle 6
- bot_cyber: Ch4.2
- cpmi_pfmi: CG.RR, PFMI.P15, PFMI.P17
- eba_ict: 3.5(a), 3.7.1, 3.7.2, 3.7.3, 3.7.5
- ecb_croe: CROE.2.5.2, CROE.2.5.3
- ffiec_is: III.D
- hipaa_sr: §164.308(a)(7)(i), §164.308(a)(7)(ii)(B), §164.308(a)(7)(ii)(C), §164.308(a)(7)(ii)(E), §164.310(a)(2)(i), §164.312(a)(2)(ii)
- iosco_cyber: PFMI-17, RR-2, RR-5
- nydfs_500: 500.2, 500.16
- sebi_cscrf: BCP-DR, CCMP, RC.CO, RC.IM, RC.RP
- nerc_cip: CIP-009-6
- nrc_73_54: RG5.71-B-CP
- doe_c2m2: RESPONSE
- api_1164: Sec 11
- awia: Sec 2013(b)
- iaea_nss: Sec 8
- isae_3402: Clause 4
- fca_sysc_13: SYSC 13.8.1, SYSC 13.8.2, SYSC 13.9.5
- fda_cyber: SA-6
- hitrust_csf: 09.b, 09.d, 12.a, 12.b
- iso_27799: 9.2, 17.1, 17.2
- lloyds_ms: CRM.3, MS8.6, MS9.1
- naic_ds: 4, 4F-b
- nhs_dspt: NDG-7.1, NDG-7.2, NDG-7.4
- pra_ss1_23: P-IT.3
- solvency_ii: DR.266, DR.266-BCP, DR.274, EIOPA-Cloud-GL11, EIOPA-ICT-4.10
- csa_ccm_v4: BCR-01, BCR-02, BCR-03, BCR-04, BCR-05, BCR-07, BCR-09, IVS-02
- csa_aicm: BCR-01, BCR-02, BCR-03, BCR-04, BCR-05, BCR-07, BCR-09, I&S-02
- ccss_v9: 1.06.1, 1.06.4
- mica: Art.47(1), Art.62(6), Art.68(5)
- basel_sco60: SCO60.21, SCO60.23, SCO60.50, SCO60.53, SCO60.63
- bssc: GSP-06, NOS-07
- sec_custody_digital: SEC-CD-12
- dpdpa: Rules.6(1)(d)
OSA's mapping for iso_27001_2022 and nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/CP-02
- Clauses only: /api/v1/controls/CP-02?fields=mappings
- Page for people: /controls/cp-02/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
