|CP-4 (1) Coordinate With Related Plans ||MODERATE |
Plans related to contingency plans for organizational information systems include, for example, Business Continuity Plans, Disaster Recovery Plans, Continuity of Operations Plans, Crisis Communications Plans, Critical Infrastructure Plans, Cyber Incident Response Plans, and Occupant Emergency Plans. This control enhancement does not require organizations to create organizational elements to handle related plans or to align such elements with specific plans. It does require, however, that if such organizational elements are responsible for related plans, organizations should coordinate with those elements.
The organization coordinates contingency plan testing with organizational elements responsible for related plans.
|CP-4 (2) Alternate Processing Site ||HIGH |
The organization tests the contingency plan at the alternate processing site: CP-4 (2)(a)
To familiarize contingency personnel with the facility and available resources; and CP-4 (2)(b)
To evaluate the capabilities of the alternate processing site to support contingency operations.
|CP-4 (3) Automated Testing || |
Automated mechanisms provide more thorough and effective testing of contingency plans, for example: (i) by providing more complete coverage of contingency issues; (ii) by selecting more realistic test scenarios and environments; and (iii) by effectively stressing the information system and supported missions.
The organization employs automated mechanisms to more thoroughly and effectively test the contingency plan.