{
  "node_id": "contingency-planning-guide-federal-systems",
  "title": "Contingency Planning Guide for Federal Information Systems",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2010-05-01",
  "bluf": "NIST Special Publication 800-34, Rev. 1, provides instructions, recommendations, and considerations for federal information system contingency planning. Contingency planning refers to interim measures to recover information system services after a disruption, which may include relocation to an alternate site, recovery using alternate equipment, or performance of functions using manual methods. The guide defines a seven-step contingency planning process for organizations to develop and maintain a viable program: 1) Develop the contingency planning policy statement; 2) Conduct the business impact analysis (BIA) to identify and prioritize critical systems; 3) Identify preventive controls to reduce disruption effects; 4) Create thorough recovery strategies; 5) Develop a detailed information system contingency plan; 6) Ensure plan testing, training, and exercises to validate capabilities and improve preparedness; and 7) Ensure the plan is a living document, updated regularly.\n\nThis guidance is for federal agencies and may be used by non-governmental organizations on a voluntary basis. It addresses specific contingency planning recommendations for client/server systems, telecommunications systems, and mainframe systems. The guidance presents sample formats for developing a contingency plan based on low-, moderate-, or high-impact levels as defined by FIPS 199. The core obligation is to establish thorough plans, procedures, and technical measures that enable a system to be recovered as quickly and effectively as possible following a service disruption, integrating these steps into each stage of the system development life cycle.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "nist-sp-800-53-r5",
    "fips-199-security-categorization"
  ],
  "primary_citations_count": 8
}