NIST SP 800-53 Rev 5
CP - Contingency Planning

NIST SP 800-53 Rev 5 NIST800-CP-2: CP-2 Contingency Plan

a. Develop a contingency plan for the system that: 1. Identifies essential mission and business functions and associated contingency requirements; 2. Provides recovery objectives, restoration priorities, and metrics; 3. Addresses contingency roles, responsibilities, assigned individuals with contact information; 4. Addresses maintaining essential mission and business functions despite a system disruption, compromise, or failure; 5. Addresses eventual, full system restoration without deterioration of the controls originally planned and implemented; 6. Addresses the sharing of contingency information; and 7. Is reviewed and approved by [Assignment: organization-defined personnel or roles]; b. Distribute copies of the contingency plan to [Assignment: organization-defined key contingency personnel (identified by name and/or by role) and organizational elements]; c. Coordinate contingency planning activities with incident handling activities; d. Review the contingency plan for the system [Assignment: organization-defined frequency]; e. Update the contingency plan to address changes to the organization, system, or environment of operation and problems encountered during contingency plan implementation, execution, or testing; f. Communicate contingency plan changes to [Assignment: organization-defined key contingency personnel (identified by name and/or by role) and organizational elements]; g. Incorporate lessons learned from contingency plan testing, training, or actual contingency activities into contingency testing and training; and h. Protect the contingency plan from unauthorized disclosure and modification.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 96 controls across 29 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 22301:2019 · 19 controls

  • 4.3.2 Scope of the business continuity management system
  • 5.3 Roles, responsibilities and authorities
  • 6.2 Business continuity objectives and planning to achieve them
  • 6.2.1 Establishing business continuity objectives
  • 7.5 Documented information
  • 7.5.2 Creating and updating
  • 7.5.3 Control of documented information
  • 8.1 Operational planning and control
  • 8.2 Business impact analysis and risk assessment
  • 8.2.2 Business impact analysis
  • 8.3 Business continuity strategies and solutions
  • 8.3.2 Identification of strategies and solutions
  • 8.3.3 Selection of strategies and solutions
  • 8.4 Business continuity plans and procedures
  • 8.4.1 General
  • 8.4.2 Response structure
  • 8.4.3 Warning and communication
  • 8.4.4 Business continuity plans
  • 8.6 Evaluation of business continuity documentation and capabilities
  • CPS230-20 Prevention, Adaptation and Return to Normal Operations
  • CPS230-26 Critical Operations Register, Continuity Plan and Activation
  • CPS230-8 Board Oversight, Approval of the BCP, Tolerance Levels and Service Provider Policy
  • CPS230-P40 Required Content of the Business Continuity Plan
  • CPS230-P45 Annual Update of the Business Continuity Plan
  • 39 Para 39 Required content of the BCP
  • NIST-CSF-DE.AE-04 The estimated impact and scope of adverse events are understood
  • NIST-CSF-GV.OC-05 Outcomes, capabilities, and services that the organization depends on are understood and communicated
  • NIST-CSF-GV.SC-08 Relevant suppliers and other third parties are included in incident planning, response, and recovery activities
  • NIST-CSF-ID.IM-04 Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved
  • NIST-CSF-RC.CO-03 Recovery activities and progress in restoring operational capabilities are communicated to designated internal and external stakeholders
  • NIST-CSF-RC.RP-02 Recovery actions are selected, scoped, prioritized, and performed

FedRAMP High · 5 controls

  • CP-2 Contingency Plan
  • CP-2(1) Coordinate with Related Plans
  • CP-2(3) Resume Mission and Business Functions
  • CP-2(8) Contingency Plan | Identify Critical Assets (CP-2(8))
  • IR-3 Incident Response Testing

FedRAMP Moderate · 5 controls

  • CP-2 Contingency Plan
  • CP-2(1) Coordinate with Related Plans
  • CP-2(3) Resume Mission and Business Functions
  • CP-2(8) Contingency Plan | Identify Critical Assets (CP-2(8))
  • IR-3 Incident Response Testing

HIPAA Security Rule · 5 controls

NIST SP 800-66 Rev 2 · 5 controls

ISO 27001:2022 · 4 controls

  • 5.24 Information security incident management planning and preparation 
  • 5.29 Information security during disruption
  • 5.30 ICT readiness for business continuity
  • 8.13 Information backup

SOC 2 · 4 controls

  • SOC2-A1.1 A1.1 Managing processing capacity
  • SOC2-A1.2 A1.2 Environmental protection, backup and recovery infrastructure
  • SOC2-A1.3 A1.3 Testing recovery plan procedures
  • SOC2-CC9.1 CC9.1 Mitigating risks of business disruption

ISO 27002:2022 · 3 controls

  • 5.29 Information security during disruption
  • 5.30 ICT readiness for business continuity
  • 5.37 Documented operating procedures
  • ASBv3-GS-8 Define and implement backup and recovery strategy
  • BR-1 Ensure regular automated backups

C5 (Germany) · 2 controls

  • C5-BCM-02 Business impact analysis policies and instructions
  • C5-BCM-03 Planning business continuity
  • CFTC-SS-24 Periodic Update of the Recovery Plan and Emergency Procedures
  • CFTC-SS-8 Business Continuity and Disaster Recovery Plan and Resources

CIS Controls v8 · 2 controls

  • CIS-11.1 Establish and Maintain a Data Recovery Process
  • CIS-11.5 Test Data Recovery

DORA · 2 controls

ISO 27701:2019 · 2 controls

  • 6.14 Information security aspects of business continuity management
  • 6.14.1 Information security continuity
  • E8-BACKUP-ML1 Regular Backups (ML1)
  • ANSSI-HYG-37 Define and Apply a Backup Policy for Critical Components

APRA CPS 234 · 1 control

  • CPS234-P24 Information Security Response Plans
  • ASD37-35 Business continuity and disaster recovery plans (Very Good)
  • AEO-12 Crisis Management and Incident Recovery

NIS2 Directive · 1 control

  • Art.21.2.c Business continuity, backup management, disaster recovery and crisis management

NIST SP 800-207 · 1 control

  • CP-2 CP-2 Contingency Plan
  • CP-2 CP-2 Contingency Plan
  • CP-2 CP-2 Contingency Plan

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in CP - Contingency Planning

You are reading one control. How much of NIST SP 800-53 Rev 5 have you already done?

NIST SP 800-53 Rev 5 NIST800-CP-2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST SP 800-53 Rev 5 your existing evidence covers. Hold ISO 27001:2022 and 163 of 1014 NIST SP 800-53 Rev 5 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 342 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 96 it maps to, and the evidence behind each claim, over MCP and REST.