Skip to main content
MuonPartners
Services
Architecture

Solution design and technology roadmapping

Solution AssessmentTechnology RoadmapsIntegration DesignSolution ArchitectureTechnical Design
Cyber Security

Security assessments, IAM, and compliance

AssessmentsIAMComplianceSecurity BaselineCyber Innovation
Network and Platform

Network architecture and cloud platforms

Network DesignCloud StrategyModernisation
Enterprise Architecture

Business-technology alignment

Business AlignmentPortfolio AnalysisGovernance
View all services
ProjectsCase StudiesInsightsToolsAbout
Contact Us

Services

Architecture
Solution AssessmentTechnology RoadmapsIntegration DesignSolution ArchitectureTechnical Design
Cyber Security
AssessmentsIAMComplianceSecurity BaselineCyber Innovation
Network and Platform
Network DesignCloud StrategyModernisation
Enterprise Architecture
Business AlignmentPortfolio AnalysisGovernance
ProjectsCase StudiesInsightsToolsAboutContact
Get in Touch
MuonPartners

Strategic technology consulting for Australian organisations navigating complexity.

Services

  • Architecture
  • Cyber Security
  • Network and Platform
  • Enterprise Architecture

Company

  • About
  • Products
  • Frameworks
  • Cross-Framework Mapping
  • Projects
  • Case Studies
  • Insights
  • Contact

Contact

  • [email protected]
  • Australia
  • LinkedIn

© 2026 Muon Partners. All rights reserved.

ABN 50 669 022 315 · A Muon Group company.

Privacy PolicyTerms of Service
  1. Frameworks
  2. >SP 800-53
  3. >Contingency Planning
  4. >SP800-53-CP-2
SP800-53-CP-2Active

Contingency Plan

Statement

Develop a contingency plan for the system that: Identifies essential mission and business functions and associated contingency requirements; Provides recovery objectives, restoration priorities, and metrics; Addresses contingency roles, responsibilities, assigned individuals with contact information; Addresses maintaining essential mission and business functions despite a system disruption, compromise, or failure; Addresses eventual, full system restoration without deterioration of the controls originally planned and implemented; Addresses the sharing of contingency information; and Is reviewed and approved by personnel or roles; key contingency personnel; organizational elements; frequency; Distribute copies of the contingency plan to personnel or roles; key contingency personnel; organizational elements; frequency; Coordinate contingency planning activities with incident handling activities; Review the contingency plan for the system frequency; Update the contingency plan to address changes to the organization, system, or environment of operation and problems encountered during contingency plan implementation, execution, or testing; Communicate contingency plan changes to personnel or roles; key contingency personnel; organizational elements; frequency; Incorporate lessons learned from contingency plan testing, training, or actual contingency activities into contingency testing and training; and Protect the contingency plan from unauthorized disclosure and modification.

Location

Control Family
Contingency Planning

Control Details

Identifier
SP800-53-CP-2
Family
CP

Organisation-Defined Parameters

cp-02_odp.01
personnel or roles
cp-02_odp.02
personnel or roles
cp-02_odp.03
key contingency personnel
cp-02_odp.04
organizational elements
cp-02_odp.05
frequency
cp-02_odp.06
key contingency personnel
cp-02_odp.07
organizational elements

Supplemental Guidance

Contingency planning for systems is part of an overall program for achieving continuity of operations for organizational mission and business functions. Contingency planning addresses system restoration and implementation of alternative mission or business processes when systems are compromised or breached. Contingency planning is considered throughout the system development life cycle and is a fundamental part of the system design. Systems can be designed for redundancy, to provide backup capabilities, and for resilience. Contingency plans reflect the degree of restoration required for organizational systems since not all systems need to fully recover to achieve the level of continuity of operations desired. System recovery objectives reflect applicable laws, executive orders, directives, regulations, policies, standards, guidelines, organizational risk tolerance, and system impact level.

Actions addressed in contingency plans include orderly system degradation, system shutdown, fallback to a manual mode, alternate information flows, and operating in modes reserved for when systems are under attack. By coordinating contingency planning with incident handling activities, organizations ensure that the necessary planning activities are in place and activated in the event of an incident. Organizations consider whether continuity of operations during an incident conflicts with the capability to automatically disable the system, as specified in IR-4(5) . Incident response planning is part of contingency planning for organizations and is addressed in the IR (Incident Response) family.

Assessment Objective

a contingency plan for the system is developed that identifies essential mission and business functions and associated contingency requirements; a contingency plan for the system is developed that provides recovery objectives; a contingency plan for the system is developed that provides restoration priorities; a contingency plan for the system is developed that provides metrics; a contingency plan for the system is developed that addresses contingency roles; a contingency plan for the system is developed that addresses contingency responsibilities; a contingency plan for the system is developed that addresses assigned individuals with contact information; a contingency plan for the system is developed that addresses maintaining essential mission and business functions despite a system disruption, compromise, or failure; a contingency plan for the system is developed that addresses eventual, full-system restoration without deterioration of the controls originally planned and implemented; a contingency plan for the system is developed that addresses the sharing of contingency information; a contingency plan for the system is developed that is reviewed by personnel or roles; a contingency plan for the system is developed that is approved by personnel or roles; copies of the contingency plan are distributed to key contingency personnel; copies of the contingency plan are distributed to organizational elements; contingency planning activities are coordinated with incident handling activities; the contingency plan for the system is reviewed frequency; the contingency plan is updated to address changes to the organization, system, or environment of operation; the contingency plan is updated to address problems encountered during contingency plan implementation, execution, or testing; contingency plan changes are communicated to key contingency personnel; contingency plan changes are communicated to organizational elements; lessons learned from contingency plan testing or actual contingency activities are incorporated into contingency testing; lessons learned from contingency plan training or actual contingency activities are incorporated into contingency testing and training; the contingency plan is protected from unauthorized disclosure; the contingency plan is protected from unauthorized modification.

ATTACK
ATTACK-T1486relatedvia ctid-attack-to-sp800-53
ATTACK-T1490relatedvia ctid-attack-to-sp800-53
ATTACK-T1491relatedvia ctid-attack-to-sp800-53
ATTACK-T1491.001relatedvia ctid-attack-to-sp800-53
ATTACK-T1491.002relatedvia ctid-attack-to-sp800-53
View in graphReport an issue
← Back to Contingency Planning
Contingency Planning56 controls
SP800-53-CP-1Policy and ProceduresSP800-53-CP-2Contingency PlanSP800-53-CP-2(1)Coordinate with Related PlansSP800-53-CP-2(2)Capacity PlanningSP800-53-CP-2(3)Resume Mission and Business FunctionsSP800-53-CP-2(4)Resume All Mission and Business FunctionsSP800-53-CP-2(5)Continue Mission and Business FunctionsSP800-53-CP-2(6)Alternate Processing and Storage SitesSP800-53-CP-2(7)Coordinate with External Service ProvidersSP800-53-CP-2(8)Identify Critical AssetsSP800-53-CP-3Contingency TrainingSP800-53-CP-3(1)Simulated EventsSP800-53-CP-3(2)Mechanisms Used in Training EnvironmentsSP800-53-CP-4Contingency Plan TestingSP800-53-CP-4(1)Coordinate with Related PlansSP800-53-CP-4(2)Alternate Processing SiteSP800-53-CP-4(3)Automated TestingSP800-53-CP-4(4)Full Recovery and ReconstitutionSP800-53-CP-4(5)Self-challengeSP800-53-CP-5Contingency Plan UpdateSP800-53-CP-6Alternate Storage SiteSP800-53-CP-6(1)Separation from Primary SiteSP800-53-CP-6(2)Recovery Time and Recovery Point ObjectivesSP800-53-CP-6(3)AccessibilitySP800-53-CP-7Alternate Processing SiteSP800-53-CP-7(1)Separation from Primary SiteSP800-53-CP-7(2)AccessibilitySP800-53-CP-7(3)Priority of ServiceSP800-53-CP-7(4)Preparation for UseSP800-53-CP-7(5)Equivalent Information Security SafeguardsSP800-53-CP-7(6)Inability to Return to Primary SiteSP800-53-CP-8Telecommunications ServicesSP800-53-CP-8(1)Priority of Service ProvisionsSP800-53-CP-8(2)Single Points of FailureSP800-53-CP-8(3)Separation of Primary and Alternate ProvidersSP800-53-CP-8(4)Provider Contingency PlanSP800-53-CP-8(5)Alternate Telecommunication Service TestingSP800-53-CP-9System BackupSP800-53-CP-9(1)Testing for Reliability and IntegritySP800-53-CP-9(2)Test Restoration Using SamplingSP800-53-CP-9(3)Separate Storage for Critical InformationSP800-53-CP-9(4)Protection from Unauthorized ModificationSP800-53-CP-9(5)Transfer to Alternate Storage SiteSP800-53-CP-9(6)Redundant Secondary SystemSP800-53-CP-9(7)Dual Authorization for Deletion or DestructionSP800-53-CP-9(8)Cryptographic ProtectionSP800-53-CP-10System Recovery and ReconstitutionSP800-53-CP-10(1)Contingency Plan TestingSP800-53-CP-10(2)Transaction RecoverySP800-53-CP-10(3)Compensating Security ControlsSP800-53-CP-10(4)Restore Within Time PeriodSP800-53-CP-10(5)Failover CapabilitySP800-53-CP-10(6)Component ProtectionSP800-53-CP-11Alternate Communications ProtocolsSP800-53-CP-12Safe ModeSP800-53-CP-13Alternative Security Mechanisms