|
controlCP-2

Contingency Plan (CP-2)

Develop a contingency plan for the system that: Distribute copies of the contingency plan to [organization-defined]; Coordinate contingency planning activities with incident handling activities; Review the contingency plan for the system [organization-defined]; Update the contingency plan to address changes to the organization, system, or environment of operation and problems encountered during contingency plan implementation, execution, or testing; Communicate contingency plan changes to [organ

Security Baselines

LOWMODERATEHIGH
contingencydisaster-recoverybusiness-continuity

Why These Connect

Maps To16

These are equivalent or closely aligned requirements in other frameworks.

Baselined In3

This control is included in the linked security baseline (LOW, MODERATE, or HIGH).

Supports51

These related controls work together — a change to one may affect the others.

Mitigates4

This control helps defend against or reduce the risk of the linked threat technique.

Enhances8

These enhancements add specific capabilities or refinements to the base control.

Cross-Framework Mappings(16)

ID.IM-01ID.IM-01Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ID.IM-02ID.IM-02Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ID.IM-03ID.IM-03Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ID.IM-04ID.IM-04Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
PR.IR-02PR.IR-02Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
RC.RP-03RC.RP-03Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
RC.CO-04RC.CO-04Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ISO 27001ISO/IEC 27001:20226 mappingsFinal
NIST OLIR informative reference — SP 800-53 Rev 5 to ISO/IEC 27001:2022
HIPAAHIPAA Security Rule7 mappingsFinal
NIST OLIR informative reference — HIPAA Security Rule to SP 800-53 Rev 5
ID.IM-01ID.IM-01Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ID.IM-02ID.IM-02Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ID.IM-03ID.IM-03Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ID.IM-04ID.IM-04Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
PR.IR-02PR.IR-02Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
RC.RP-03RC.RP-03Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
RC.CO-04RC.CO-04Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5

Organization-Defined Parameters(7)

Assignmentorganization-defined personnel or roles
Assignmentorganization-defined personnel or roles
Assignmentorganization-defined key contingency personnel
Assignmentorganization-defined organizational elements
Assignmentorganization-defined frequency
Assignmentorganization-defined key contingency personnel
Assignmentorganization-defined organizational elements

Control Enhancements(8)