Contingency Planning (CP)
Program-specific policies and procedures shall be included in the specific security controls listed below. There is no requirement for the Program to develop additional policy to meet the -1 control. For additional information on the types of contingency plans, review the section in the DAA PM.
Recommended Continuous Monitoring Frequency: Annual
Program Frequency:
CONTINUOUS MONITORING STRATEGY
Click here to enter text.
CP-2 – Contingency Plan – Maybe tailor out based on contract requirements.
Recommended Continuous Monitoring Frequency: Annual
Program Frequency:
Distributes copies of the contingency plan to personnel or roles and organizational elements identified in the contingency plan via an information sharing capability
Click here to enter text.
Coordinates contingency planning activities with incident handling activities
Click here to enter text.
Reviews the contingency plan for the information system at least annually
Click here to enter text.
Updates the contingency plan to address changes to the organization, information system, or environment of operation and problems encountered during contingency plan implementation, execution, or testing
Click here to enter text.
Communicates contingency plan changes to stakeholders identified in the contingency plan
Click here to enter text.
Protects the contingency plan from unauthorized disclosure and modification
Click here to enter text.
CONTINUOUS MONITORING STRATEGY
Click here to enter text.
Recommended Continuous Monitoring Frequency: Annual
Program Frequency:
CONTINUOUS MONITORING STRATEGY
Click here to enter text.
CP-4 – Contingency Plan Testing and Exercises
Recommended Continuous Monitoring Frequency: Annual
Program Frequency:
Documents and reviews the contingency plan test/exercise results, identifies weaknesses and initiates corrective actions if needed
Click here to enter text.
CONTINUOUS MONITORING STRATEGY
Click here to enter text.
CP-7 – Alternate Processing Site
After a relevance determination, this control can be tailored out for standalone IS.
Recommended Continuous Monitoring Frequency: Annual
Program Frequency:
Ensure that equipment and supplies required to resume operations are available at the alternate site or contracts are in place to support delivery to the site in time to support the organization-defined time period for resumption
Tailored out, low availability impact
Ensure that the alternate processing site provides information security safeguards equivalent to that of the primary site
Tailored out, low availability impact
Develop alternate processing site agreements (e.g., MOA/MOU) that contain priority-of-service provisions in accordance with the organization’s availability requirements
Tailored out, low availability impact
CONTINUOUS MONITORING STRATEGY
Click here to enter text.
Recommended Continuous Monitoring Frequency: Weekly
Program Frequency:
Conduct backups of information system documentation including security-related documentation when created or received, when updated, and as required by system baseline configuration changes in accordance with the contingency plan.
Click here to enter text.
Conduct backups of information system documentation including security-related documentation when created or received, when updated, and as required by system baseline configuration changes in accordance with the contingency plan.
Click here to enter text.
Protects the confidentiality, integrity, and availability of backup information at storage locations
Click here to enter text.
CONTINUOUS MONITORING STRATEGY
Click here to enter text.
CONTINUOUS MONITORING STRATEGY
Click here to enter text.
Recommended Continuous Monitoring Frequency: Annual
Program Frequency:
CONTINUOUS MONITORING STRATEGY
Click here to enter text.
Share with your friends: |