NIST Special Publication 800-34 Revision 1, Contingency Planning Guide for Federal Information Systems
ISCP Development

NIST Special Publication 800-34 Revision 1, Contingency Planning Guide for Federal Information Systems 4: Information System Contingency Plan (ISCP) Development

Develop the Information System Contingency Plan (ISCP) per NIST SP 800-34 Rev 1 Section 3.5 + Appendix A (Sample ISCP Template). ISCP must include (a) Supporting Information per Section 3.5.1: introduction + concept of operations + system description and architecture + ISCP overview, (b) Activation and Notification Phase per Section 3.5.2: activation criteria + notification procedures + outage assessment criteria + decision authority for plan activation, (c) Recovery Phase per Section 3.5.3: sequence of recovery activities + execution priorities + recovery procedures per resource + escalation paths + status reporting + decision authority for recovery decisions, (d) Reconstitution Phase per Section 3.5.4: validation of system functionality + concurrent processing + system testing + transition to normal operations + lessons-learned capture + ISCP update triggers, (e) Plan Appendices per Section 3.5.5 + Appendix A: personnel contacts + vendor contacts + alternate procedures + system configuration + system requirements + applications and data inventory + agreements and other documentation. Plan must align with FIPS 199 system categorisation impact level (Low/Moderate/High) per Appendix F (Sample Plans per Impact Level).

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.