CP-1
Contingency Planning
Policy and Procedures
Description
a. Develop, document, and disseminate to [organization-defined parameter]: b. Designate an [organization-defined parameter] to manage the development, documentation, and dissemination of the contingency planning policy and procedures; and c. Review and update the current contingency planning:
Mapped SPARTA techniques
No techniques mapped to this control.
Cross-framework references
Relationships published by the source frameworks themselves, reproduced here with attribution. They are not SafeMode Space mappings and carry no confidence rating of ours.
Referenced by 9 in NIST Cybersecurity Framework 2.0
- GV.OC-03Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed
- GV.OV-01Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction
- GV.PO-01Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced
- GV.PO-02Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission
- GV.SC-03Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes
- GV.SC-08Relevant suppliers and other third parties are included in incident planning, response, and recovery activities
- ID.IM-01Improvements are identified from evaluations
- ID.IM-02Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties
- ID.IM-03Improvements are identified from execution of operational processes, procedures, and activities
Cite as SafeMode Space, nist-80053-rev5 CP-1.