// Level 3 · Controls

Contingency Planning

NIST SP 800-53 Rev 5 Contingency Planning controls.

CP-01Medium

Policy and Procedures

Develop, document, and disseminate to [parameter]:

CP-02Medium

Contingency Plan

Develop a contingency plan for the system that:

CP-03Medium

Contingency Training

Provide contingency training to system users consistent with assigned roles and responsibilities:

CP-04Medium

Contingency Plan Testing

Test the contingency plan for the system [parameter] using the following tests to determine the effectiveness of the plan and the readiness to execute the plan: [parameter].

CP-05Medium

Contingency Plan Update

Contingency Plan Update

CP-06Medium

Alternate Storage Site

Establish an alternate storage site, including necessary agreements to permit the storage and retrieval of system backup information; and

CP-07Medium

Alternate Processing Site

Establish an alternate processing site, including necessary agreements to permit the transfer and resumption of [parameter] for essential mission and business functions within [parameter] when the primary processing capabilities are unavailable;

CP-08Medium

Telecommunications Services

Establish alternate telecommunications services, including necessary agreements to permit the resumption of [parameter] for essential mission and business functions within [parameter] when the primary telecommunications capabilities are unavailable at either the primary or alternate processing or storage sites.

CP-09Medium

System Backup

Conduct backups of user-level information contained in [parameter] [parameter];

CP-10Medium

System Recovery and Reconstitution

Provide for the recovery and reconstitution of the system to a known state within [parameter] after a disruption, compromise, or failure.

CP-11Medium

Alternate Communications Protocols

Provide the capability to employ [parameter] in support of maintaining continuity of operations.

CP-12Medium

Safe Mode

When [parameter] are detected, enter a safe mode of operation with [parameter].

CP-13Medium

Alternative Security Mechanisms

Employ [parameter] for satisfying [parameter] when the primary means of implementing the security function is unavailable or compromised.