NIST SP 800-66 Rev 2
Administrative

NIST SP 800-66 Rev 2 164.308(a)(7)(i): Contingency Plan (Standard)

Establish policies for responding to emergencies that damage ePHI systems. NIST recommends contingency planning per SP 800-34 with business impact analysis driving recovery priorities.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 58 controls across 24 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 22301:2019 · 11 controls

  • 4.2.1 General
  • 4.3.1 General
  • 6.1.1 Determining risks and opportunities
  • 8.1 Operational planning and control
  • 8.2.1 General
  • 8.2.2 Business impact analysis
  • 8.4 Business continuity plans and procedures
  • 8.4.1 General
  • 8.4.4 Business continuity plans
  • 8.4.5 Recovery
  • 8.5 Exercise programme

ISO 27001:2022 · 5 controls

  • 5.23 Information security for use of cloud services
  • 5.24 Information security incident management planning and preparation 
  • 5.29 Information security during disruption
  • 5.30 ICT readiness for business continuity
  • 8.13 Information backup

NIST SP 800-53 Rev 5 · 5 controls

  • NIST-CSF-GV.OC-04 Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated
  • NIST-CSF-ID.IM-04 Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved
  • NIST-CSF-PR.DS-11 Backups of data are created, protected, maintained, and tested
  • NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process

SOC 2 · 4 controls

  • SOC2-A1.3 A1.3 Testing recovery plan procedures
  • SOC2-CC3.4 CC3.4 Identifying and assessing significant changes (COSO principle 9)
  • SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11)
  • SOC2-CC9.1 CC9.1 Mitigating risks of business disruption
  • CFTC-SS-22 Business Continuity and Disaster Recovery Planning Category
  • CFTC-SS-37 Protection of Swap Data Repository Data
  • CFTC-SS-8 Business Continuity and Disaster Recovery Plan and Resources

ISO 27701:2019 · 3 controls

  • 6.11 Systems acquisition, development and maintenance
  • 6.14.1 Information security continuity
  • 6.9 Operations security
  • CPS230-26 Critical Operations Register, Continuity Plan and Activation
  • CPS230-P40 Required Content of the Business Continuity Plan
  • CCM-BCR-01 Business Continuity Management Policy and Procedures
  • CCM-BCR-04 Business Continuity Planning

FedRAMP High · 2 controls

  • CP-1 Policy and Procedures
  • CP-2 Contingency Plan

FedRAMP Moderate · 2 controls

  • CP-1 Policy and Procedures
  • CP-2 Contingency Plan

ISO 27002:2022 · 2 controls

  • 5.29 Information security during disruption
  • 5.30 ICT readiness for business continuity

NIST SP 800-161 Rev 1 · 2 controls

  • E8-BACKUP-ML1 Regular Backups (ML1)
  • ANSSI-HYG-37 Define and Apply a Backup Policy for Critical Components
  • CPS220-P35 Required Content of Risk Management Policies and Procedures

APRA CPS 234 · 1 control

  • ASD37-35 Business continuity and disaster recovery plans (Very Good)
  • AEO-12 Crisis Management and Incident Recovery
  • ASBv3-GS-8 Define and implement backup and recovery strategy

C5 (Germany) · 1 control

CIS Controls v8 · 1 control

  • CIS-11.1 Establish and Maintain a Data Recovery Process

PCI DSS 4.0 · 1 control

  • 12.10.1 12.10.1 Incident response plan ready for activation

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Administrative

Query this from an agent

The graph holds this control, the 58 it maps to, and the evidence behind each claim, over MCP and REST.