STIGhubSTIGhub
STIGsRMF ControlsCompare
STIGhub— A free STIG search and compliance tool·STIGs updated 3 days ago
Powered by Pylon·Privacy·Terms·© 2026 Beacon Cloud Solutions, Inc.
← All Controls

CP-2

Contingency PlanningRev 5organization

Contingency Plan

Baselines:LowModerateHigh

Control Statement

a. Develop a contingency plan for the system that: 1. Identifies essential mission and business functions and associated contingency requirements; 2. Provides recovery objectives, restoration priorities, and metrics; 3. Addresses contingency roles, responsibilities, assigned individuals with contact information; 4. Addresses maintaining essential mission and business functions despite a system disruption, compromise, or failure; 5. Addresses eventual, full system restoration without deterioration of the controls originally planned and implemented; 6. Addresses the sharing of contingency information; and 7. Is reviewed and approved by [Assignment: organization-defined personnel or roles]; b. Distribute copies of the contingency plan to [Assignment: organization-defined key contingency personnel (identified by name and/or by role) and organizational elements]; c. Coordinate contingency planning activities with incident handling activities; d. Review the contingency plan for the system [Assignment: frequency]; e. Update the contingency plan to address changes to the organization, system, or environment of operation and problems encountered during contingency plan implementation, execution, or testing; f. Communicate contingency plan changes to [Assignment: organization-defined key contingency personnel (identified by name and/or by role) and organizational elements]; g. Incorporate lessons learned from contingency plan testing, training, or actual contingency activities into contingency testing and training; and h. Protect the contingency plan from unauthorized disclosure and modification.

Supplemental Guidance

Contingency planning for systems is part of an overall program for achieving continuity of operations for organizational mission and business functions. Contingency planning addresses system restoration and implementation of alternative mission or business processes when systems are compromised or breached. Contingency planning is considered throughout the system development life cycle and is a fundamental part of the system design. Systems can be designed for redundancy, to provide backup capabilities, and for resilience. Contingency plans reflect the degree of restoration required for organizational systems since not all systems need to fully recover to achieve the level of continuity of operations desired. System recovery objectives reflect applicable laws, executive orders, directives, regulations, policies, standards, guidelines, organizational risk tolerance, and system impact level. Actions addressed in contingency plans include orderly system degradation, system shutdown, fallback to a manual mode, alternate information flows, and operating in modes reserved for when systems are under attack. By coordinating contingency planning with incident handling activities, organizations ensure that the necessary planning activities are in place and activated in the event of an incident. Organizations consider whether continuity of operations during an incident conflicts with the capability to automatically disable the system, as specified in [IR-4(5)](#ir-4.5) . Incident response planning is part of contingency planning for organizations and is addressed in the [IR](#ir) (Incident Response) family.

Related Controls (25)

CP-3CP-4CP-6CP-7CP-8CP-9CP-10CP-11CP-13IR-4IR-6IR-8IR-9MA-6MP-2MP-4MP-5PL-2PM-8PM-11SA-15

CCI Identifiers (32)

CCI-002831Defines a list of key contingency personnel (identified by name and/or by role) and organizational elements to whom contingency plan changes are to be communicated.CCI-002832Protects the contingency plan from unauthorized disclosure and modification.CCI-004006Develop a contingency plan for the system that addresses maintaining essential mission functions despite a system disruption, compromise, or failure.CCI-004007Develop a contingency plan for the system that addresses maintaining essential business functions despite a system disruption, compromise, or failure.CCI-004008Develop a contingency plan for the system that addresses the sharing of contingency information.CCI-004009Incorporate lessons learned from contingency plan testing, training, or actual contingency activities into contingency testing and training.CCI-000443Develop a contingency plan for the system that identifies essential missions.CCI-000444Develop a contingency plan for the system that identifies essential business functions.

Linked STIG Checks (2)

Across 1 STIGs. Click to expand.

SA-20
SC-7
SC-23
SI-12
CCI-000445Develop a contingency plan for the system that identifies associated contingency requirements.
CCI-000446Develop a contingency plan for the system that provides recovery objectives.
CCI-000447Develop a contingency plan for the system that provides restoration priorities.
CCI-000448Develop a contingency plan for the system that provides metrics.
CCI-000449Develop a contingency plan for the system that addresses contingency roles, responsibilities, assigned individuals with contact information.
CCI-000450The organization develops a contingency plan for the information system that addresses maintaining essential missions despite an information system disruption.
CCI-000451The organization develops a contingency plan for the information system that addresses maintaining essential business functions despite an information system disruption.
CCI-000452The organization develops a contingency plan for the information system that addresses maintaining essential missions despite an information system compromise.
CCI-000453The organization develops a contingency plan for the information system that addresses maintaining essential business functions despite an information system compromise.
CCI-000454The organization develops a contingency plan for the information system that addresses maintaining essential missions despite an information system failure.
CCI-000455The organization develops a contingency plan for the information system that addresses maintaining essential business functions despite an information system failure.
CCI-000456Develop a contingency plan for the system that addresses eventual, full system restoration without deterioration of the controls originally planned and implemented.
CCI-000457Develop a contingency plan for the system that is reviewed and approved by organization-defined personnel or roles.
CCI-000458Defines the key contingency personnel (identified by name and/or by role) and organizational elements designated to receive copies of the contingency plan.
CCI-000459Distributes copies of the contingency plan to an organization-defined list of key contingency personnel (identified by name and/or by role) and organizational elements.
CCI-000460Coordinate contingency planning activities with incident handling activities.
CCI-000461Defines the frequency with which to review the contingency plan for the system.
CCI-000462Reviews the contingency plan for the system in accordance with organization-defined frequency.
CCI-000463Updates the contingency plan to address changes to the organization.
CCI-000464Updates the contingency plan to address changes to the system.
CCI-000465Updates the contingency plan to address changes to the environment of operation.
CCI-000466Updates the contingency plan to address problems encountered during contingency plan implementation, execution, or testing.
CCI-000468Communicates contingency plan changes to an organization-defined list of key contingency personnel (identified by name and/or by role) and organizational elements.
CCI-002830Defines the personnel or roles who review and approve the contingency plan for the system.