Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

NIST SP 800-53 Learning Center

CP-2 — Contingency Plan

Read the official control and assessment content, then use the separately labeled Bare Metal Cyber perspective to connect the requirement to implementation, evidence, and sustained operation.

8Enhancements
10Parameters
3Baseline memberships
3Assessment methods

CP — Contingency Planning · NIST SP 800-53 Release 5.2.0

LowModerateHigh
Official NIST control content

Control statement

  1. a.Develop a contingency plan for the system that:
    1. 1.Identifies essential mission and business functions and associated contingency requirements;
    2. 2.Provides recovery objectives, restoration priorities, and metrics;
    3. 3.Addresses contingency roles, responsibilities, assigned individuals with contact information;
    4. 4.Addresses maintaining essential mission and business functions despite a system disruption, compromise, or failure;
    5. 5.Addresses eventual, full system restoration without deterioration of the controls originally planned and implemented;
    6. 6.Addresses the sharing of contingency information; and
    7. 7.Is reviewed and approved by [Organization-defined: organization-defined personnel or roles];
  2. b.Distribute copies of the contingency plan to [Organization-defined: organization-defined key contingency personnel (identified by name and/or by role) and organizational elements];
  3. c.Coordinate contingency planning activities with incident handling activities;
  4. d.Review the contingency plan for the system [Organization-defined: frequency];
  5. e.Update the contingency plan to address changes to the organization, system, or environment of operation and problems encountered during contingency plan implementation, execution, or testing;
  6. f.Communicate contingency plan changes to [Organization-defined: organization-defined key contingency personnel (identified by name and/or by role) and organizational elements];
  7. g.Incorporate lessons learned from contingency plan testing, training, or actual contingency activities into contingency testing and training; and
  8. h.Protect the contingency plan from unauthorized disclosure and modification.
Official NIST discussion

Discussion

Contingency planning for systems is part of an overall program for achieving continuity of operations for organizational mission and business functions. Contingency planning addresses system restoration and implementation of alternative mission or business processes when systems are compromised or breached. Contingency planning is considered throughout the system development life cycle and is a fundamental part of the system design. Systems can be designed for redundancy, to provide backup capabilities, and for resilience. Contingency plans reflect the degree of restoration required for organizational systems since not all systems need to fully recover to achieve the level of continuity of operations desired. System recovery objectives reflect applicable laws, executive orders, directives, regulations, policies, standards, guidelines, organizational risk tolerance, and system impact level. Actions addressed in contingency plans include orderly system degradation, system shutdown, fallback to a manual mode, alternate information flows, and operating in modes reserved for when systems are under attack. By coordinating contingency planning with incident handling activities, organizations ensure that the necessary planning activities are in place and activated in the event of an incident. Organizations consider whether continuity of operations during an incident conflicts with the capability to automatically disable the system, as specified in [IR-4(5)](#ir-4.5) . Incident response planning is part of contingency planning for organizations and is addressed in the [IR](#ir) (Incident Response) family.

Official OSCAL parameters

Organization-defined parameters

These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.

organization-defined personnel or roles
organization-defined key contingency personnel (identified by name and/or by role) and organizational elements
organization-defined key contingency personnel (identified by name and/or by role) and organizational elements
personnel or rolespersonnel or roles to review a contingency plan is/are defined;
personnel or rolespersonnel or roles to approve a contingency plan is/are defined;
key contingency personnelkey contingency personnel (identified by name and/or by role) to whom copies of the contingency plan are distributed are defined;
organizational elementskey contingency organizational elements to which copies of the contingency plan are distributed are defined;
frequencyfrequency of contingency plan review is defined;
key contingency personnelkey contingency personnel (identified by name and/or by role) to communicate changes to are defined;
organizational elementskey contingency organizational elements to communicate changes to are defined;
Original Bare Metal Cyber perspective

From control text to operational evidence

Use Contingency Plan as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to resilient operations, recovery priorities, alternate capabilities, and tested restoration.

Implementation workflow

  • Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
  • Resolve each organization-defined parameter before declaring the control implemented.
  • Document how the implementation satisfies every clause of the official control statement.
  • Collect evidence as a normal byproduct of operation rather than only before an assessment.
  • Review exceptions, changes, and monitoring results on a risk-based cadence.

Evidence examples

  • contingency and recovery plans
  • backup success and restoration-test records
  • exercise after-action reports
  • alternate processing or communications agreements

Common failure patterns

  • backups never restored in testing
  • recovery priorities not tied to mission impact
  • plans dependent on unavailable people or facilities
  • exercise findings not tracked to closure

Questions practitioners should ask

  • What risk decision is this control intended to support in this system?
  • Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
  • Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
  • What event or threshold requires the implementation to be reviewed or changed?
Official NIST SP 800-53A content

Assessment objectives and methods

Show the assessment objective
  1. CP-02a.
    1. CP-02a.01a contingency plan for the system is developed that identifies essential mission and business functions and associated contingency requirements;
    2. CP-02a.02
      1. CP-02a.02[01]a contingency plan for the system is developed that provides recovery objectives;
      2. CP-02a.02[02]a contingency plan for the system is developed that provides restoration priorities;
      3. CP-02a.02[03]a contingency plan for the system is developed that provides metrics;
    3. CP-02a.03
      1. CP-02a.03[01]a contingency plan for the system is developed that addresses contingency roles;
      2. CP-02a.03[02]a contingency plan for the system is developed that addresses contingency responsibilities;
      3. CP-02a.03[03]a contingency plan for the system is developed that addresses assigned individuals with contact information;
    4. CP-02a.04a contingency plan for the system is developed that addresses maintaining essential mission and business functions despite a system disruption, compromise, or failure;
    5. CP-02a.05a contingency plan for the system is developed that addresses eventual, full-system restoration without deterioration of the controls originally planned and implemented;
    6. CP-02a.06a contingency plan for the system is developed that addresses the sharing of contingency information;
    7. CP-02a.07
      1. CP-02a.07[01]a contingency plan for the system is developed that is reviewed by [Organization-defined: personnel or roles];
      2. CP-02a.07[02]a contingency plan for the system is developed that is approved by [Organization-defined: personnel or roles];
  2. CP-02b.
    1. CP-02b.[01]copies of the contingency plan are distributed to [Organization-defined: key contingency personnel];
    2. CP-02b.[02]copies of the contingency plan are distributed to [Organization-defined: organizational elements];
  3. CP-02c.contingency planning activities are coordinated with incident handling activities;
  4. CP-02d.the contingency plan for the system is reviewed [Organization-defined: frequency];
  5. CP-02e.
    1. CP-02e.[01]the contingency plan is updated to address changes to the organization, system, or environment of operation;
    2. CP-02e.[02]the contingency plan is updated to address problems encountered during contingency plan implementation, execution, or testing;
  6. CP-02f.
    1. CP-02f.[01]contingency plan changes are communicated to [Organization-defined: key contingency personnel];
    2. CP-02f.[02]contingency plan changes are communicated to [Organization-defined: organizational elements];
  7. CP-02g.
    1. CP-02g.[01]lessons learned from contingency plan testing or actual contingency activities are incorporated into contingency testing;
    2. CP-02g.[02]lessons learned from contingency plan training or actual contingency activities are incorporated into contingency testing and training;
  8. CP-02h.
    1. CP-02h.[01]the contingency plan is protected from unauthorized disclosure;
    2. CP-02h.[02]the contingency plan is protected from unauthorized modification.

Examine

  • Contingency planning policy
  • procedures addressing contingency operations for the system
  • contingency plan
  • evidence of contingency plan reviews and updates
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with contingency planning and plan implementation responsibilities
  • organizational personnel with incident handling responsibilities
  • organizational personnel with knowledge of requirements for mission and business functions
  • organizational personnel with information security responsibilities

Test

  • Organizational processes for contingency plan development, review, update, and protection
  • mechanisms for developing, reviewing, updating, and/or protecting the contingency plan
Official relationships

Related controls

These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.

Official NIST enhancements

Control enhancements

Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.

Official NIST control enhancement

CP-2(1) — Coordinate with Related Plans

ModerateHigh

Coordinate contingency plan development with organizational elements responsible for related plans.

Official discussion

Plans that are related to contingency plans include Business Continuity Plans, Disaster Recovery Plans, Critical Infrastructure Plans, Continuity of Operations Plans, Crisis Communications Plans, Insider Threat Implementation Plans, Data Breach Response Plans, Cyber Incident Response Plans, Breach Response Plans, and Occupant Emergency Plans.

Assessment objectives and methods

contingency plan development is coordinated with organizational elements responsible for related plans.

Examine

  • Contingency planning policy
  • procedures addressing contingency operations for the system
  • contingency plan
  • business contingency plans
  • disaster recovery plans
  • continuity of operations plans
  • crisis communications plans
  • critical infrastructure plans
  • cyber incident response plan
  • insider threat implementation plans
  • occupant emergency plans
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with contingency planning and plan implementation responsibilities
  • organizational personnel with information security responsibilities
  • personnel with responsibility for related plans
Official NIST control enhancement

CP-2(2) — Capacity Planning

High

Conduct capacity planning so that necessary capacity for information processing, telecommunications, and environmental support exists during contingency operations.

Official discussion

Capacity planning is needed because different threats can result in a reduction of the available processing, telecommunications, and support services intended to support essential mission and business functions. Organizations anticipate degraded operations during contingency operations and factor the degradation into capacity planning. For capacity planning, environmental support refers to any environmental factor for which the organization determines that it needs to provide support in a contingency situation, even if in a degraded state. Such determinations are based on an organizational assessment of risk, system categorization (impact level), and organizational risk tolerance.

Assessment objectives and methods
  1. CP-02(02)[01]capacity planning is conducted so that the necessary capacity exists during contingency operations for information processing;
  2. CP-02(02)[02]capacity planning is conducted so that the necessary capacity exists during contingency operations for telecommunications;
  3. CP-02(02)[03]capacity planning is conducted so that the necessary capacity exists during contingency operations for environmental support.

Examine

  • Contingency planning policy
  • procedures addressing contingency operations for the system
  • contingency plan
  • capacity planning documents
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with contingency planning and plan implementation responsibilities
  • organizational personnel responsible for capacity planning
  • organizational personnel with information security responsibilities
Related controls
Official NIST control enhancement

CP-2(3) — Resume Mission and Business Functions

ModerateHigh

Plan for the resumption of [Organization-defined: cp-02.03_odp.01] mission and business functions within [Organization-defined: time period] of contingency plan activation.

Official discussion

Organizations may choose to conduct contingency planning activities to resume mission and business functions as part of business continuity planning or as part of business impact analyses. Organizations prioritize the resumption of mission and business functions. The time period for resuming mission and business functions may be dependent on the severity and extent of the disruptions to the system and its supporting infrastructure.

Organization-defined parameters (2)
cp-02.03_odp.01
time periodthe contingency plan activation time period within which to resume mission and business functions is defined;
Assessment objectives and methods

the resumption of [Organization-defined: cp-02.03_odp.01] mission and business functions are planned for within [Organization-defined: time period] of contingency plan activation.

Examine

  • Contingency planning policy
  • procedures addressing contingency operations for the system
  • contingency plan
  • business impact assessment
  • system security plan
  • privacy plan
  • other related plans
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with contingency planning and plan implementation responsibilities
  • organizational personnel with information security and privacy responsibilities
  • organizational personnel with knowledge of requirements for mission and business functions

Test

  • Organizational processes for resumption of missions and business functions
Official NIST control enhancement

CP-2(4) — Resume All Mission and Business Functions

Withdrawn

This enhancement is marked withdrawn in the official OSCAL catalog. Related-control metadata below may identify where its intent was incorporated.

Official NIST control enhancement

CP-2(5) — Continue Mission and Business Functions

High

Plan for the continuance of [Organization-defined: cp-02.05_odp] mission and business functions with minimal or no loss of operational continuity and sustains that continuity until full system restoration at primary processing and/or storage sites.

Official discussion

Organizations may choose to conduct the contingency planning activities to continue mission and business functions as part of business continuity planning or business impact analyses. Primary processing and/or storage sites defined by organizations as part of contingency planning may change depending on the circumstances associated with the contingency.

Organization-defined parameters (1)
cp-02.05_odp
Assessment objectives and methods
  1. CP-02(05)[01]the continuance of [Organization-defined: cp-02.05_odp] mission and business functions with minimal or no loss of operational continuity is planned for;
  2. CP-02(05)[02]continuity is sustained until full system restoration at primary processing and/or storage sites.

Examine

  • Contingency planning policy
  • procedures addressing contingency operations for the system
  • contingency plan
  • business impact assessment
  • primary processing site agreements
  • primary storage site agreements
  • alternate processing site agreements
  • alternate storage site agreements
  • contingency plan test documentation
  • contingency plan test results
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with contingency planning and plan implementation responsibilities
  • organizational personnel with knowledge of requirements for mission and business functions
  • organizational personnel with information security responsibilities

Test

  • Organizational processes for continuing missions and business functions
Official NIST control enhancement

CP-2(6) — Alternate Processing and Storage Sites

Plan for the transfer of [Organization-defined: cp-02.06_odp] mission and business functions to alternate processing and/or storage sites with minimal or no loss of operational continuity and sustain that continuity through system restoration to primary processing and/or storage sites.

Official discussion

Organizations may choose to conduct contingency planning activities for alternate processing and storage sites as part of business continuity planning or business impact analyses. Primary processing and/or storage sites defined by organizations as part of contingency planning may change depending on the circumstances associated with the contingency.

Organization-defined parameters (1)
cp-02.06_odp
Assessment objectives and methods
  1. CP-02(06)[01]the transfer of [Organization-defined: cp-02.06_odp] mission and business functions to alternate processing and/or storage sites with minimal or no loss of operational continuity is planned for;
  2. CP-02(06)[02]operational continuity is sustained until full system restoration at primary processing and/or storage sites.

Examine

  • Contingency planning policy
  • procedures addressing contingency operations for the system
  • contingency plan
  • business impact assessment
  • alternate processing site agreements
  • alternate storage site agreements
  • contingency plan testing documentation
  • contingency plan test results
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with contingency planning and plan implementation responsibilities
  • organizational personnel with knowledge of requirements for mission and business functions
  • organizational personnel with information security responsibilities

Test

  • Organizational processes for transfer of essential mission and business functions to alternate processing/storage sites
Official NIST control enhancement

CP-2(7) — Coordinate with External Service Providers

Coordinate the contingency plan with the contingency plans of external service providers to ensure that contingency requirements can be satisfied.

Official discussion

When the capability of an organization to carry out its mission and business functions is dependent on external service providers, developing a comprehensive and timely contingency plan may become more challenging. When mission and business functions are dependent on external service providers, organizations coordinate contingency planning activities with the external entities to ensure that the individual plans reflect the overall contingency needs of the organization.

Assessment objectives and methods

the contingency plan is coordinated with the contingency plans of external service providers to ensure that contingency requirements can be satisfied.

Examine

  • Contingency planning policy
  • procedures addressing contingency operations for the system
  • contingency plan
  • contingency plans of external
  • service providers
  • service level agreements
  • contingency plan requirements
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with contingency planning and plan implementation responsibilities
  • external service providers
  • organizational personnel with information security responsibilities
Related controls
Official NIST control enhancement

CP-2(8) — Identify Critical Assets

ModerateHigh

Identify critical system assets supporting [Organization-defined: cp-02.08_odp] mission and business functions.

Official discussion

Organizations may choose to identify critical assets as part of criticality analysis, business continuity planning, or business impact analyses. Organizations identify critical system assets so that additional controls can be employed (beyond the controls routinely implemented) to help ensure that organizational mission and business functions can continue to be conducted during contingency operations. The identification of critical information assets also facilitates the prioritization of organizational resources. Critical system assets include technical and operational aspects. Technical aspects include system components, information technology services, information technology products, and mechanisms. Operational aspects include procedures (i.e., manually executed operations) and personnel (i.e., individuals operating technical controls and/or executing manual procedures). Organizational program protection plans can assist in identifying critical assets. If critical assets are resident within or supported by external service providers, organizations consider implementing [CP-2(7)](#cp-2.7) as a control enhancement.

Organization-defined parameters (1)
cp-02.08_odp
Assessment objectives and methods

critical system assets supporting [Organization-defined: cp-02.08_odp] mission and business functions are identified.

Examine

  • Contingency planning policy
  • procedures addressing contingency operations for the system
  • contingency plan
  • business impact assessment
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with contingency planning and plan implementation responsibilities
  • organizational personnel with knowledge of requirements for mission and business functions
  • organizational personnel with information security responsibilities
Related controls
Source record

Authoritative sources