NIST 800-53 REV 5 • CONTINGENCY PLANNING
CP-2(5) — Continue Mission and Business Functions
Plan for the continuance of {{ insert: param, cp-02.05_odp }} mission and business functions with minimal or no loss of operational continuity and sustains that continuity until full system restoration at primary processing and/or storage sites.
CMMC Practice Mapping
No direct CMMC mapping
NIST 800-171 Mapping
No direct NIST 800-171 mapping
Related Controls
No related controls listed
Supplemental Guidance
Organizations may choose to conduct the contingency planning activities to continue mission and business functions as part of business continuity planning or business impact analyses. Primary processing and/or storage sites defined by organizations as part of contingency planning may change depending on the circumstances associated with the contingency.
Practitioner Notes
This enhancement requires the ability to continue essential functions with minimal or no interruption — true high availability rather than just recovery after a disruption.
Example 1: Deploy critical applications across multiple Azure Availability Zones or AWS Regions so that if one zone fails, the application automatically fails over to another.
Example 2: Implement Always On Availability Groups for your SQL Server databases with automatic failover to a secondary replica in a different data center.