NIST 800-53 REV 5 • CONTINGENCY PLANNING
CP-2(3) — Resume Mission and Business Functions
Plan for the resumption of {{ insert: param, cp-02.03_odp.01 }} mission and business functions within {{ insert: param, cp-02.03_odp.02 }} of contingency plan activation.
CMMC Practice Mapping
No direct CMMC mapping
NIST 800-171 Mapping
No direct NIST 800-171 mapping
Related Controls
No related controls listed
Supplemental Guidance
Organizations may choose to conduct contingency planning activities to resume mission and business functions as part of business continuity planning or as part of business impact analyses. Organizations prioritize the resumption of mission and business functions. The time period for resuming mission and business functions may be dependent on the severity and extent of the disruptions to the system and its supporting infrastructure.
Practitioner Notes
This enhancement requires your contingency plan to address resuming essential mission and business functions within a defined time period after a disruption.
Example 1: Define specific Recovery Time Objectives (RTOs) for each critical function — for example, email within 4 hours, ERP within 8 hours, file shares within 24 hours.
Example 2: Document the sequence of system restoration in your plan: restore Active Directory first, then DNS, then email, then business applications, ensuring dependencies are addressed in order.