{
  "node_id": "nist-sp-800-34-r1",
  "title": "Contingency Planning Guide for Federal Information Systems",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2010-05-01",
  "bluf": "NIST Special Publication 800-34, Rev. 1 provides instructions, recommendations, and considerations for federal information system contingency planning. Contingency planning refers to a coordinated strategy involving interim measures to recover information system services after a disruption. These measures may include relocation of systems to an alternate site, recovery using alternate equipment, or performing functions using manual methods. This guide is prepared for use by federal agencies but may be used by nongovernmental organizations on a voluntary basis.\n\nThe core obligation is a seven-step contingency planning process: 1. Develop a formal contingency planning policy statement to provide authority and guidance. 2. Conduct a business impact analysis (BIA) to identify and prioritize critical information systems and components. 3. Identify preventive controls to reduce the effects of system disruptions. 4. Create thorough recovery strategies to ensure the system may be recovered quickly and effectively. 5. Develop a detailed information system contingency plan. 6. Ensure plan testing, training, and exercises to validate recovery capabilities and prepare personnel. 7. Ensure the plan is a living document that is updated regularly to remain current with system enhancements and organizational changes.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "nist-sp-800-53-r5",
    "fips-199-security-categorization",
    "nist-sp-800-39-managing-risk"
  ],
  "primary_citations_count": 8
}