← Controls / CP

CP-02 Contingency Plan

Contingency Planning

Low Moderate High

Description

a. Develop a contingency plan for the system that: 1. Identifies essential mission and business functions and associated contingency requirements; 2. Provides recovery objectives, restoration priorities, and metrics; 3. Addresses contingency roles, responsibilities, assigned individuals with contact information; 4. Addresses maintaining essential mission and business functions despite a system disruption, compromise, or failure; 5. Addresses eventual, full system restoration without deterioration of the controls originally planned and implemented; 6. Addresses the sharing of contingency information; and 7. Is reviewed and approved by [Assignment: organization-defined personnel or roles]; b. Distribute copies of the contingency plan to [Assignment: organization-defined key contingency personnel (identified by name and/or by role) and organizational elements]; c. Coordinate contingency planning activities with incident handling activities; d. Review the contingency plan for the system [Assignment: organization-defined frequency]; e. Update the contingency plan to address changes to the organization, system, or environment of operation and problems encountered during contingency plan implementation, execution, or testing; f. Communicate contingency plan changes to [Assignment: organization-defined key contingency personnel (identified by name and/or by role) and organizational elements]; g. Incorporate lessons learned from contingency plan testing, training, or actual contingency activities into contingency testing and training; and h. Protect the contingency plan from unauthorized disclosure and modification.

Supplemental Guidance

Contingency planning for systems is part of an overall program for achieving continuity of operations for organizational mission and business functions. Contingency planning addresses system restoration and implementation of alternative mission or business processes when systems are compromised or breached. Contingency planning is considered throughout the system development life cycle and is a fundamental part of the system design. Systems can be designed for redundancy, to provide backup capabilities, and for resilience. Contingency plans reflect the degree of restoration required for organizational systems since not all systems need to fully recover to achieve the level of continuity of operations desired. System recovery objectives reflect applicable laws, executive orders, directives, regulations, policies, standards, guidelines, organizational risk tolerance, and system impact level. Actions addressed in contingency plans include orderly system degradation, system shutdown, fallback to a manual mode, alternate information flows, and operating in modes reserved for when systems are under attack. By coordinating contingency planning with incident handling activities, organizations ensure that the necessary planning activities are in place and activated in the event of an incident. Organizations consider whether continuity of operations during an incident conflicts with the capability to automatically disable the system, as specified in IR-04(05). Incident response planning is part of contingency planning for organizations and is addressed in the IR (Incident Response) family.

Changes from Rev 4

Develop and document a map of system data actions, addressing the sharing of contingency information and noting the system operations that process personally identifiable information; incorporate lessons learned into contingency planning tests and training

Enhancements (7)

What NIST adds to this control. Select one to read its statement.

CP-02(01) Coordinate with Related Plans ModerateHigh

Coordinate contingency plan development with organizational elements responsible for related plans.

CP-02(02) Capacity Planning High

Conduct capacity planning so that necessary capacity for information processing, telecommunications, and environmental support exists during contingency operations.

CP-02(03) Resume Mission and Business Functions ModerateHigh

Plan for the resumption of [Selection (one): all; essential] mission and business functions within [Assignment: organization-defined time period] of contingency plan activation.

CP-02(05) Continue Mission and Business Functions High

Plan for the continuance of [Selection (one): all; essential] mission and business functions with minimal or no loss of operational continuity and sustains that continuity until full system restoration at primary processing and/or storage sites.

CP-02(06) Alternate Processing and Storage Sites

Plan for the transfer of [Selection (one): all; essential] mission and business functions to alternate processing and/or storage sites with minimal or no loss of operational continuity and sustain that continuity through system restoration to primary processing and/or storage sites.

CP-02(07) Coordinate with External Service Providers

Coordinate the contingency plan with the contingency plans of external service providers to ensure that contingency requirements can be satisfied.

CP-02(08) Identify Critical Assets ModerateHigh

Identify critical system assets supporting [Selection (one): all; essential] mission and business functions.

Withdrawn by NIST:

  • CP-02(04) Resume All Mission and Business Functions, now in CP-02(03)

Compliance Mappings

ISO 27001:2022

7.5A.5.2A.5.29A.5.30A.8.6A.8.14

ISO 27002:2022

5.295.308.6

COBIT 2019

BAI04DSS04

CIS Controls v8

CIS 11.1

NIST CSF 2.0

GV.OC-04GV.OC-05GV.SC-08ID.AM-05ID.IM-01ID.IM-02ID.IM-03ID.IM-04PR.IR-02PR.IR-03PR.IR-04RC.CO-03RC.CO-04RC.RP-01RC.RP-02RC.RP-03

SOC 2 TSC

A1.2A1.2-POF1A1.2-POF2A1.2-POF3CC7.4-POF5CC7.5CC9.1CC9.1-POF1

CSA CCM v4

BCR-01BCR-02BCR-03BCR-04BCR-05BCR-07BCR-09IVS-02

CSA AICM v1

BCR-01BCR-02BCR-03BCR-04BCR-05BCR-07BCR-09I&S-02

ISO 42001:2023

A.4.5

IEC 62443

3-3 SR 7.2

NIS2 Directive

Art. 21(2)(c)

PRA Operational Resilience

SS1/21-3.1SS1/21-4.1SS1/21-5.1SS1/21-8.1SS1/21-10.1SS2/21-10.1SS2/21-12.1

MAS TRM

8

BSI IT-Grundschutz

DER.4

ANSSI

Hygiene.30Hygiene.35SecNumCloud.18.1

FINMA Circular 2023/1

IV.E(87)IV.E(88)IV.E(89)IV.E(90)IV.E(91)

OSFI B-13

B-13.2.6

EU GDPR

Art.32(1)(b)Art.32(1)(c)Art.32(1)(d)

EU DORA

Art.11(1)Art.11(3)Art.11(4)Art.12(1)

BIO2

5.295.308.6

RBI CSF

Annex1.19ITGRCA.28ITGRCA.29

FISC Security Guidelines

FISC.O5

LGPD + BCB 4893

BCB.Art.3

HKMA TM-E-1

TME1.6.1TME1.6.2

MLPS 2.0

8.1.10.11

DNB Good Practice

DNB.8.3DNB.11.1DNB.11.4

EU CRA

CRA.I.2h

NCA ECC

3-13-25-1

UAE IA

T12

CBB TM

TM-14

Qatar NIA

BC

CBUAE

CR-13

CBE CSF

OVM-2

SA JS2

JS2-7.5

CBN CSF

Part3.6Part3.7

BoG CISD

CISD-BCM

POPIA

s19

BoM CTRM

5.2

IOSCO Cyber Resilience

PFMI-17RR-2RR-5

BCBS 239

Principle 2Principle 5Principle 6

CPMI-IOSCO PFMI

CG.RRPFMI.P15PFMI.P17

FFIEC IS

III.D

NYDFS 500

500.2500.16

HIPAA Security Rule

§164.308(a)(7)(i)§164.308(a)(7)(ii)(B)§164.308(a)(7)(ii)(C)§164.308(a)(7)(ii)(E)§164.310(a)(2)(i)§164.312(a)(2)(ii)

ECB CROE

CROE.2.5.2CROE.2.5.3

EBA ICT Guidelines

3.5(a)3.7.13.7.23.7.33.7.5

SEBI CSCRF

BCP-DRCCMPRC.CORC.IMRC.RP

BOT Cyber Resilience

Ch4.2

NERC CIP

CIP-009-6

10 CFR 73.54

RG5.71-B-CP

DOE C2M2 v2.1

RESPONSE

API 1164

Sec 11

AWIA

Sec 2013(b)

IAEA NSS 17-T

Sec 8

ISAE 3402

Clause 4

Solvency II

DR.266DR.266-BCPDR.274EIOPA-Cloud-GL11EIOPA-ICT-4.10

Lloyd's Minimum Standards

CRM.3MS8.6MS9.1

NAIC Insurance Data Security

44F-b

PRA SS1/23

P-IT.3

FCA SYSC 13

SYSC 13.8.1SYSC 13.8.2SYSC 13.9.5

HITRUST CSF v11

09.b09.d12.a12.b

FDA Cybersecurity Guidance

SA-6

ISO 27799

9.217.117.2

NHS DSPT

NDG-7.1NDG-7.2NDG-7.4

CCSS v9.0

1.06.11.06.4

MiCA

Art.47(1)Art.62(6)Art.68(5)

Basel SCO60

SCO60.21SCO60.23SCO60.50SCO60.53SCO60.63

BSSC Standards

GSP-06NOS-07

SEC Custody (Digital Assets)

SEC-CD-12

India DPDPA

Rules.6(1)(d)

ISO 17799 (legacy)

10.3.210.4.110.8.514.1.314.1.4

COBIT 4.1 (legacy)

DS4.2