NIST SP 800-53 Revision 5.1 HIGH
CP Contingency Planning

NIST SP 800-53 Revision 5.1 HIGH CP-2(8): Contingency Plan | Identify Critical Assets. Identify critical system assets supporting [Selection: all; essential] mission and business functions

Contingency Plan | Identify Critical Assets. Identify critical system assets supporting [Selection: all; essential] mission and business functions

What else in your programme already covers this

This control maps to 26 controls across 15 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-GV.OC-04 Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated
  • NIST-CSF-GV.OC-05 Outcomes, capabilities, and services that the organization depends on are understood and communicated
  • NIST-CSF-GV.SC-04 Suppliers are known and prioritized by criticality
  • NIST-CSF-ID.AM-01 Inventories of hardware managed by the organization are maintained
  • NIST-CSF-ID.AM-05 Assets are prioritized based on classification, criticality, resources, and impact on the mission

NIST SP 800-53 Rev 5 · 4 controls

  • NIST800-CM-8 System component inventory
  • NIST800-CP-2 Contingency plan
  • NIST800-PM-11 Mission and Business Process Definition. Define organizational mission and business processes with consideration for information security and privacy and the resulting risk to organizational operations, organizational assets, individuals, other organizations, and the Nation; and
  • NIST800-RA-9 Criticality analysis

PCI DSS 4.0 · 4 controls

  • 1.2.3 Network diagrams maintained
  • 12.10.1 Incident response plan
  • 12.10.2 IRP reviewed and tested annually
  • 12.5.1 Inventory of system components in scope
  • CPS230-17 Mandatory Minimum Classification of Critical Operations
  • CPS230-26 Critical Operations Register, Continuity Plan and Activation
  • ASBv3-DP-1 Discover, classify, and label sensitive data

C5 (Germany) · 1 control

  • C5-BCM-02 Business impact analysis policies and instructions

CIS Controls v8 · 1 control

  • CIS-1.1 Establish and Maintain Detailed Enterprise Asset Inventory

DORA · 1 control

HIPAA Security Rule · 1 control

ISO 22301:2019 · 1 control

  • 8.2.2 Business impact analysis

ISO 27002:2022 · 1 control

  • 5.9 Inventory of information and other associated assets

SOC 2 · 1 control

  • SOC2-A1.2 Environmental protections, data backups, and recovery infrastructure support availability

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in CP Contingency Planning

Query this from an agent

The graph holds this control, the 26 it maps to, and the evidence behind each claim, over MCP and REST.