NIST Special Publication 800-34 Revision 1, Contingency Planning Guide for Federal Information Systems
Contingency Planning Policy and Programme

NIST Special Publication 800-34 Revision 1, Contingency Planning Guide for Federal Information Systems 1: Contingency Planning Policy, Programme, and Plan Coordination

Establish a contingency planning policy and programme per NIST SP 800-34 Rev 1 Section 3.1 (Develop the Contingency Planning Policy Statement). Policy must define (a) scope and applicability across federal information systems + supporting infrastructure + dependencies, (b) roles and responsibilities aligned with NIST RMF (Authorising Official + System Owner + Information System Security Officer + Information System Contingency Plan Coordinator + Business Continuity Coordinator + Disaster Recovery Coordinator), (c) resource requirements + training requirements + exercise and testing schedules + plan maintenance schedule, (d) integration with other contingency-related plans per NIST SP 800-34 Rev 1 Section 2.2 covering Continuity of Operations Plan (COOP) + Business Continuity Plan (BCP) + Business Recovery Plan (BRP) + Incident Response Plan (IRP) + Disaster Recovery Plan (DRP) + Crisis Communications Plan + Information System Contingency Plan (ISCP) + Cyber Incident Response Plan (CIRP) + Occupant Emergency Plan (OEP). Coordinate authority + scope + activation criteria + handoffs between plans to avoid conflicts during real events. Policy approval by senior management + annual review + revision after significant change.

What else in your programme already covers this

This control maps to 189 controls across 119 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission
  • NG-NDPA-2 Lawful Basis, Consent, and Data Protection Principles
  • NG-NDPA-5 Security of Processing, Breach Notification, and DPIA
  • NG-NDPA-8 Enforcement, Penalties, Data Controllers of Major Importance (DCMI), and Compliance
  • 1.2 Operating System Privileged Account Control
  • 1.3 Virtualisation Platform Protection
  • 3.3 Configure Data Access Control Lists

ISO/IEC 27004:2016 · 3 controls

ISO/IEC 27011:2024 · 3 controls

ISO/IEC 27014:2020 · 3 controls

ISO/IEC 27400:2022 · 3 controls

ISO/IEC 29100:2024 · 3 controls

ISO/IEC 29134:2023 · 3 controls

ISO/IEC 29147:2018 · 3 controls

ISO/IEC 30111:2019 · 3 controls

MTCS (Singapore) · 3 controls

  • AT-DSG-2 Section 2 - Scope and application
  • AT-DSG-8 Section 22 - Functions and powers of the DPA

FedRAMP High · 2 controls

  • AC-2 Account Management
  • CA-9 Internal System Connections

FedRAMP Moderate · 2 controls

  • AC-2 Account Management
  • CA-9 Internal System Connections

FedRAMP Rev 5 · 2 controls

  • 6.5 Preparing and Distributing Audit Report
  • 6.7 Conducting Audit Follow-up

ISO 19011 · 2 controls

  • 6.5 Preparing and Distributing Audit Report
  • 6.7 Conducting Audit Follow-up
  • STANAG-1 STANAG 4774 Confidentiality Label Schema and XML Structure
  • STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding

NIST SP 800-145 · 2 controls

  • NISTSP145-1 On-Demand Self-Service and Broad Network Access Characteristics
  • NISTSP145-7 Cloud Procurement Standards Aligned to NIST SP 800-145 Definition

NIST SP 800-146 · 2 controls

  • NISTSP146-1 Cloud Adoption Strategy, Workload Suitability, and Decision Framework
  • NISTSP146-6 Cloud Security and Privacy Recommendations
  • AC-2 Account Management
  • CA-9 Internal System Connections
  • AC-2 Account Management
  • CA-9 Internal System Connections
  • AC-2 Account Management
  • CA-9 Internal System Connections
  • NISTSP82-1 OT Security Program Governance, Policy, Roles, and Safety-Security Integration
  • NISTSP82-7 OT Incident Response, Forensics, Recovery, and Continuity
  • NDPA-1 Applicability, Scope, and Carve-Outs
  • NDPA-8 Nebraska Attorney General Enforcement, Permanent 30-Day Cure, and Penalties
  • ASTWO-7 Deficiency Evaluation, Material Weakness, and Communication
  • ASTWO-8 ICFR Opinion, Basis, Definition, Limitations, Combined vs Separate Reports
  • C1 Organizational Boundary
  • C3 Scope 1 and 2 Coverage

South Korea PIPA · 2 controls

  • 4.4.1 Resources, Roles, Responsibility, and Authority

Bahrain PDPL · 1 control

COBIT 2019 · 1 control

  • R.16-VATR.Unhosted Unhosted (self-hosted / non-custodial) wallet transfers - 2024 Targeted Update
  • QMSR-ISO13485-Sec5 Management responsibility (ISO 13485:2016 Section 5 - incorporated via §820.10)
  • UAE-PDPL-Status UAE PDPL status, executive regulations, UAE Data Office guidance evolution
  • FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704)

GLBA · 1 control

GRI Standards · 1 control

HKMA SPM · 1 control

IEEE 7000 · 1 control

ISMAP (Japan) · 1 control

ISO 31000:2018 · 1 control

  • 6.7 Conducting Audit Follow-up

ISO/IEC 27007:2020 · 1 control

ISO/IEC 27031:2011 · 1 control

ISSB Standards · 1 control

India DPDP Act · 1 control

Indonesia PDP Law · 1 control

Japan AI Guidelines · 1 control

LGPD · 1 control

Liechtenstein DPA · 1 control

MITRE ATT&CK · 1 control

MITRE D3FEND · 1 control

Malaysia PDPA 2010 · 1 control

Mauritius DPA · 1 control

Mexico LFPDPPP · 1 control

  • PQC-4 FIPS 205 SLH-DSA Implementation - Stateless Hash-Based Digital Signature
  • NISTPF-1 Identify-P - Business Environment, Data Processing Inventory, Ecosystem, and Risk Assessment

NIST SP 800-122 · 1 control

  • NISTSP122-8 Continuous Monitoring, Training, and Privacy Programme Governance

NIST SP 800-123 · 1 control

NIST SP 800-137 · 1 control

  • NISTSP137-1 ISCM Strategy, Governance, and Volatility Assessment

NIST SP 800-144 · 1 control

  • NISTSP144-1 Cloud Governance, Risk Assessment, and Provider Trust Evaluation
  • 3.3 Configure Data Access Control Lists

NIST SP 800-61 · 1 control

  • NISTSP61-2 Computer Security Incident Response Team (CSIRT) Structure and Staffing

NIST SP 800-63-4 · 1 control

  • NISTSP63R4-1 Digital Identity Risk Management and IAL/AAL/FAL Assurance Level Selection

NIST SP 800-88 · 1 control

  • NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework

NIST SP 800-92 · 1 control

  • NISTSP92-1 Log Management Programme, Policy, Roles, and Operational Runbooks
  • NHPA-8 AG Formella Enforcement, Permanent 60-Day Cure, and Penalties
  • NJDPA-8 AG Platkin Enforcement, 18-Month Cure Sunset, and Division of Consumer Affairs
  • NZISM-2 Certification and Accreditation (C&A) for Government Systems
  • NGNDPR-8 Annual Data Protection Audit, Penalties, and NDPA Transition

OWASP ASVS · 1 control

  • OWASPASVS-1 Architecture, Design and Threat Modelling (V1)

PCI DSS 4.0 · 1 control

  • 2.2.2 Vendor default accounts are managed as follows: • If the vendor default account(s) will be used, the default password is changed per Requirement 8.3.6. • If the vendor default account(s) will not be used,
  • AUPRV-8 OAIC Cooperation, Vendor Management, Training, Complaints, Enforcement

SWIFT CSCF · 1 control

  • SWIFTCSCF-1 Restrict Internet Access and Protect Critical Systems (Objective 1)
  • TEFCAREC-1 Common Agreement Conformance and Onboarding
  • VIETNAMCYBER-2 Prohibited Acts (Access, Interception, Forgery, Content)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 189 it maps to, and the evidence behind each claim, over MCP and REST.