Control statement
- a.Develop a contingency plan for the system that:
- 1.Identifies essential mission and business functions and associated contingency requirements;
- 2.Provides recovery objectives, restoration priorities, and metrics;
- 3.Addresses contingency roles, responsibilities, assigned individuals with contact information;
- 4.Addresses maintaining essential mission and business functions despite a system disruption, compromise, or failure;
- 5.Addresses eventual, full system restoration without deterioration of the controls originally planned and implemented;
- 6.Addresses the sharing of contingency information; and
- 7.Is reviewed and approved by [Organization-defined: organization-defined personnel or roles];
- b.Distribute copies of the contingency plan to [Organization-defined: organization-defined key contingency personnel (identified by name and/or by role) and organizational elements];
- c.Coordinate contingency planning activities with incident handling activities;
- d.Review the contingency plan for the system [Organization-defined: frequency];
- e.Update the contingency plan to address changes to the organization, system, or environment of operation and problems encountered during contingency plan implementation, execution, or testing;
- f.Communicate contingency plan changes to [Organization-defined: organization-defined key contingency personnel (identified by name and/or by role) and organizational elements];
- g.Incorporate lessons learned from contingency plan testing, training, or actual contingency activities into contingency testing and training; and
- h.Protect the contingency plan from unauthorized disclosure and modification.
Discussion
Contingency planning for systems is part of an overall program for achieving continuity of operations for organizational mission and business functions. Contingency planning addresses system restoration and implementation of alternative mission or business processes when systems are compromised or breached. Contingency planning is considered throughout the system development life cycle and is a fundamental part of the system design. Systems can be designed for redundancy, to provide backup capabilities, and for resilience. Contingency plans reflect the degree of restoration required for organizational systems since not all systems need to fully recover to achieve the level of continuity of operations desired. System recovery objectives reflect applicable laws, executive orders, directives, regulations, policies, standards, guidelines, organizational risk tolerance, and system impact level. Actions addressed in contingency plans include orderly system degradation, system shutdown, fallback to a manual mode, alternate information flows, and operating in modes reserved for when systems are under attack. By coordinating contingency planning with incident handling activities, organizations ensure that the necessary planning activities are in place and activated in the event of an incident. Organizations consider whether continuity of operations during an incident conflicts with the capability to automatically disable the system, as specified in [IR-4(5)](#ir-4.5) . Incident response planning is part of contingency planning for organizations and is addressed in the [IR](#ir) (Incident Response) family.
Organization-defined parameters
These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.
From control text to operational evidence
Use Contingency Plan as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to resilient operations, recovery priorities, alternate capabilities, and tested restoration.
Implementation workflow
- Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
- Resolve each organization-defined parameter before declaring the control implemented.
- Document how the implementation satisfies every clause of the official control statement.
- Collect evidence as a normal byproduct of operation rather than only before an assessment.
- Review exceptions, changes, and monitoring results on a risk-based cadence.
Evidence examples
- contingency and recovery plans
- backup success and restoration-test records
- exercise after-action reports
- alternate processing or communications agreements
Common failure patterns
- backups never restored in testing
- recovery priorities not tied to mission impact
- plans dependent on unavailable people or facilities
- exercise findings not tracked to closure
Questions practitioners should ask
- What risk decision is this control intended to support in this system?
- Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
- Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
- What event or threshold requires the implementation to be reviewed or changed?
Assessment objectives and methods
Show the assessment objective
- CP-02a.
- CP-02a.01a contingency plan for the system is developed that identifies essential mission and business functions and associated contingency requirements;
- CP-02a.02
- CP-02a.02[01]a contingency plan for the system is developed that provides recovery objectives;
- CP-02a.02[02]a contingency plan for the system is developed that provides restoration priorities;
- CP-02a.02[03]a contingency plan for the system is developed that provides metrics;
- CP-02a.03
- CP-02a.03[01]a contingency plan for the system is developed that addresses contingency roles;
- CP-02a.03[02]a contingency plan for the system is developed that addresses contingency responsibilities;
- CP-02a.03[03]a contingency plan for the system is developed that addresses assigned individuals with contact information;
- CP-02a.04a contingency plan for the system is developed that addresses maintaining essential mission and business functions despite a system disruption, compromise, or failure;
- CP-02a.05a contingency plan for the system is developed that addresses eventual, full-system restoration without deterioration of the controls originally planned and implemented;
- CP-02a.06a contingency plan for the system is developed that addresses the sharing of contingency information;
- CP-02a.07
- CP-02a.07[01]a contingency plan for the system is developed that is reviewed by [Organization-defined: personnel or roles];
- CP-02a.07[02]a contingency plan for the system is developed that is approved by [Organization-defined: personnel or roles];
- CP-02b.
- CP-02b.[01]copies of the contingency plan are distributed to [Organization-defined: key contingency personnel];
- CP-02b.[02]copies of the contingency plan are distributed to [Organization-defined: organizational elements];
- CP-02c.contingency planning activities are coordinated with incident handling activities;
- CP-02d.the contingency plan for the system is reviewed [Organization-defined: frequency];
- CP-02e.
- CP-02e.[01]the contingency plan is updated to address changes to the organization, system, or environment of operation;
- CP-02e.[02]the contingency plan is updated to address problems encountered during contingency plan implementation, execution, or testing;
- CP-02f.
- CP-02f.[01]contingency plan changes are communicated to [Organization-defined: key contingency personnel];
- CP-02f.[02]contingency plan changes are communicated to [Organization-defined: organizational elements];
- CP-02g.
- CP-02g.[01]lessons learned from contingency plan testing or actual contingency activities are incorporated into contingency testing;
- CP-02g.[02]lessons learned from contingency plan training or actual contingency activities are incorporated into contingency testing and training;
- CP-02h.
- CP-02h.[01]the contingency plan is protected from unauthorized disclosure;
- CP-02h.[02]the contingency plan is protected from unauthorized modification.
Examine
- Contingency planning policy
- procedures addressing contingency operations for the system
- contingency plan
- evidence of contingency plan reviews and updates
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with contingency planning and plan implementation responsibilities
- organizational personnel with incident handling responsibilities
- organizational personnel with knowledge of requirements for mission and business functions
- organizational personnel with information security responsibilities
Test
- Organizational processes for contingency plan development, review, update, and protection
- mechanisms for developing, reviewing, updating, and/or protecting the contingency plan
Related controls
These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.
Control enhancements
Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.
CP-2(1) — Coordinate with Related Plans
Coordinate contingency plan development with organizational elements responsible for related plans.
Official discussion
Plans that are related to contingency plans include Business Continuity Plans, Disaster Recovery Plans, Critical Infrastructure Plans, Continuity of Operations Plans, Crisis Communications Plans, Insider Threat Implementation Plans, Data Breach Response Plans, Cyber Incident Response Plans, Breach Response Plans, and Occupant Emergency Plans.
Assessment objectives and methods
contingency plan development is coordinated with organizational elements responsible for related plans.
Examine
- Contingency planning policy
- procedures addressing contingency operations for the system
- contingency plan
- business contingency plans
- disaster recovery plans
- continuity of operations plans
- crisis communications plans
- critical infrastructure plans
- cyber incident response plan
- insider threat implementation plans
- occupant emergency plans
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with contingency planning and plan implementation responsibilities
- organizational personnel with information security responsibilities
- personnel with responsibility for related plans
CP-2(2) — Capacity Planning
Conduct capacity planning so that necessary capacity for information processing, telecommunications, and environmental support exists during contingency operations.
Official discussion
Capacity planning is needed because different threats can result in a reduction of the available processing, telecommunications, and support services intended to support essential mission and business functions. Organizations anticipate degraded operations during contingency operations and factor the degradation into capacity planning. For capacity planning, environmental support refers to any environmental factor for which the organization determines that it needs to provide support in a contingency situation, even if in a degraded state. Such determinations are based on an organizational assessment of risk, system categorization (impact level), and organizational risk tolerance.
Assessment objectives and methods
- CP-02(02)[01]capacity planning is conducted so that the necessary capacity exists during contingency operations for information processing;
- CP-02(02)[02]capacity planning is conducted so that the necessary capacity exists during contingency operations for telecommunications;
- CP-02(02)[03]capacity planning is conducted so that the necessary capacity exists during contingency operations for environmental support.
Examine
- Contingency planning policy
- procedures addressing contingency operations for the system
- contingency plan
- capacity planning documents
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with contingency planning and plan implementation responsibilities
- organizational personnel responsible for capacity planning
- organizational personnel with information security responsibilities
Related controls
CP-2(3) — Resume Mission and Business Functions
Plan for the resumption of [Organization-defined: cp-02.03_odp.01] mission and business functions within [Organization-defined: time period] of contingency plan activation.
Official discussion
Organizations may choose to conduct contingency planning activities to resume mission and business functions as part of business continuity planning or as part of business impact analyses. Organizations prioritize the resumption of mission and business functions. The time period for resuming mission and business functions may be dependent on the severity and extent of the disruptions to the system and its supporting infrastructure.
Organization-defined parameters (2)
Assessment objectives and methods
the resumption of [Organization-defined: cp-02.03_odp.01] mission and business functions are planned for within [Organization-defined: time period] of contingency plan activation.
Examine
- Contingency planning policy
- procedures addressing contingency operations for the system
- contingency plan
- business impact assessment
- system security plan
- privacy plan
- other related plans
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with contingency planning and plan implementation responsibilities
- organizational personnel with information security and privacy responsibilities
- organizational personnel with knowledge of requirements for mission and business functions
Test
- Organizational processes for resumption of missions and business functions
CP-2(4) — Resume All Mission and Business Functions
This enhancement is marked withdrawn in the official OSCAL catalog. Related-control metadata below may identify where its intent was incorporated.
CP-2(5) — Continue Mission and Business Functions
Plan for the continuance of [Organization-defined: cp-02.05_odp] mission and business functions with minimal or no loss of operational continuity and sustains that continuity until full system restoration at primary processing and/or storage sites.
Official discussion
Organizations may choose to conduct the contingency planning activities to continue mission and business functions as part of business continuity planning or business impact analyses. Primary processing and/or storage sites defined by organizations as part of contingency planning may change depending on the circumstances associated with the contingency.
Organization-defined parameters (1)
Assessment objectives and methods
- CP-02(05)[01]the continuance of [Organization-defined: cp-02.05_odp] mission and business functions with minimal or no loss of operational continuity is planned for;
- CP-02(05)[02]continuity is sustained until full system restoration at primary processing and/or storage sites.
Examine
- Contingency planning policy
- procedures addressing contingency operations for the system
- contingency plan
- business impact assessment
- primary processing site agreements
- primary storage site agreements
- alternate processing site agreements
- alternate storage site agreements
- contingency plan test documentation
- contingency plan test results
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with contingency planning and plan implementation responsibilities
- organizational personnel with knowledge of requirements for mission and business functions
- organizational personnel with information security responsibilities
Test
- Organizational processes for continuing missions and business functions
CP-2(6) — Alternate Processing and Storage Sites
Plan for the transfer of [Organization-defined: cp-02.06_odp] mission and business functions to alternate processing and/or storage sites with minimal or no loss of operational continuity and sustain that continuity through system restoration to primary processing and/or storage sites.
Official discussion
Organizations may choose to conduct contingency planning activities for alternate processing and storage sites as part of business continuity planning or business impact analyses. Primary processing and/or storage sites defined by organizations as part of contingency planning may change depending on the circumstances associated with the contingency.
Organization-defined parameters (1)
Assessment objectives and methods
- CP-02(06)[01]the transfer of [Organization-defined: cp-02.06_odp] mission and business functions to alternate processing and/or storage sites with minimal or no loss of operational continuity is planned for;
- CP-02(06)[02]operational continuity is sustained until full system restoration at primary processing and/or storage sites.
Examine
- Contingency planning policy
- procedures addressing contingency operations for the system
- contingency plan
- business impact assessment
- alternate processing site agreements
- alternate storage site agreements
- contingency plan testing documentation
- contingency plan test results
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with contingency planning and plan implementation responsibilities
- organizational personnel with knowledge of requirements for mission and business functions
- organizational personnel with information security responsibilities
Test
- Organizational processes for transfer of essential mission and business functions to alternate processing/storage sites
CP-2(7) — Coordinate with External Service Providers
Coordinate the contingency plan with the contingency plans of external service providers to ensure that contingency requirements can be satisfied.
Official discussion
When the capability of an organization to carry out its mission and business functions is dependent on external service providers, developing a comprehensive and timely contingency plan may become more challenging. When mission and business functions are dependent on external service providers, organizations coordinate contingency planning activities with the external entities to ensure that the individual plans reflect the overall contingency needs of the organization.
Assessment objectives and methods
the contingency plan is coordinated with the contingency plans of external service providers to ensure that contingency requirements can be satisfied.
Examine
- Contingency planning policy
- procedures addressing contingency operations for the system
- contingency plan
- contingency plans of external
- service providers
- service level agreements
- contingency plan requirements
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with contingency planning and plan implementation responsibilities
- external service providers
- organizational personnel with information security responsibilities
Related controls
CP-2(8) — Identify Critical Assets
Identify critical system assets supporting [Organization-defined: cp-02.08_odp] mission and business functions.
Official discussion
Organizations may choose to identify critical assets as part of criticality analysis, business continuity planning, or business impact analyses. Organizations identify critical system assets so that additional controls can be employed (beyond the controls routinely implemented) to help ensure that organizational mission and business functions can continue to be conducted during contingency operations. The identification of critical information assets also facilitates the prioritization of organizational resources. Critical system assets include technical and operational aspects. Technical aspects include system components, information technology services, information technology products, and mechanisms. Operational aspects include procedures (i.e., manually executed operations) and personnel (i.e., individuals operating technical controls and/or executing manual procedures). Organizational program protection plans can assist in identifying critical assets. If critical assets are resident within or supported by external service providers, organizations consider implementing [CP-2(7)](#cp-2.7) as a control enhancement.
Organization-defined parameters (1)
Assessment objectives and methods
critical system assets supporting [Organization-defined: cp-02.08_odp] mission and business functions are identified.
Examine
- Contingency planning policy
- procedures addressing contingency operations for the system
- contingency plan
- business impact assessment
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with contingency planning and plan implementation responsibilities
- organizational personnel with knowledge of requirements for mission and business functions
- organizational personnel with information security responsibilities
Related controls
Authoritative sources
Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST. Official control requirements and interpretations remain with NIST and the responsible authorizing organization.