{
  "node_id": "nist-contingency-planning-federal-systems",
  "title": "Contingency Planning Guide for Federal Information Systems",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2010-05-21",
  "bluf": "NIST Special Publication 800-34, Rev. 1, provides instructions, recommendations, and considerations for federal information system contingency planning. Contingency planning refers to interim measures to recover information system services after a disruption, which may include relocation to an alternate site, recovery using alternate equipment, or performance of functions using manual methods. This guidance addresses contingency planning recommendations for client/server, telecommunications, and mainframe systems.\n\nThe guide defines a seven-step contingency planning process to develop and maintain a viable program. These steps are: 1. Develop the contingency planning policy statement to provide authority and guidance. 2. Conduct the business impact analysis (BIA) to identify and prioritize critical information systems. 3. Identify preventive controls to reduce the effects of system disruptions. 4. Create thorough recovery strategies to ensure the system may be recovered quickly and effectively. 5. Develop an information system contingency plan containing detailed guidance and procedures. 6. Ensure plan testing, training, and exercises to validate recovery capabilities and identify gaps. 7. Ensure plan maintenance, treating the plan as a living document that is updated regularly.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "nist-sp-800-53-r5",
    "fips-199-security-categorization"
  ],
  "primary_citations_count": 8
}