{
  "node_id": "nist-sp-800-34-contingency-planning",
  "title": "Contingency Planning Guide for Federal Information Systems",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2010-05-01",
  "bluf": "NIST Special Publication 800-34, Rev. 1 provides instructions, recommendations, and considerations for federal information system contingency planning. Contingency planning refers to interim measures and a coordinated strategy involving plans, procedures, and technical measures that enable the recovery of information systems, operations, and data after a service disruption. Interim measures may include relocation of information systems to an alternate site, recovery using alternate equipment, or performance of functions using manual methods. This guidance is prepared for use by federal agencies but may be used by nongovernmental organizations on a voluntary basis. It applies to managers, CIOs, security officers, system engineers, and administrators responsible for designing, managing, operating, or securing information systems.\n\nThe core obligation for federal organizations is to apply a seven-step process to develop and maintain a viable contingency planning program for their information systems. This process includes: developing a formal contingency planning policy statement; conducting a business impact analysis (BIA) to identify and prioritize critical systems; identifying preventive controls to reduce disruption effects; creating thorough recovery strategies; developing a detailed information system contingency plan (ISCP); ensuring the plan is validated through testing, training, and exercises; and maintaining the plan as a living document. These progressive steps are designed to be integrated into each stage of the system development life cycle, ensuring that systems can be recovered quickly and effectively following a disruption.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "fips-199-security-categorization"
  ],
  "primary_citations_count": 8
}