Policy and Procedures CP-1
Contingency Planning · Low baseline ✗ Not implemented
Status — program-wide
What references this control
No risks name this control in their Framework field yet.
No policies reference it yet.
Link a risk or policy to this control
Attaching adds CP-1 to the item's Framework field; the ✨ AI button suggests the best match. You can also edit the Framework field on a risk / policy directly.
Source: NIST SP 800-53 Rev.5, Contingency Planning family NIST SP 800-53 Rev.5. The baseline shows the lowest SP 800-53B baseline (Low / Moderate / High) this control appears in NIST SP 800-53B.
Control guide — plain-English, per NIST SP 800-53
CP-1 (Contingency Planning — Policy and Procedures) is the written foundation for everything else in the Contingency Planning family: a policy that says why the organization plans for outages and who is responsible, plus the procedures that put that policy into practice. It names an owner, sets a review schedule, and is usually the first thing an auditor asks to see. It is a Low-baseline control, so it applies from the very start.
What good looks like
- Write a short contingency planning policy that covers purpose, scope, roles, responsibilities, and how it lines up with any laws or standards you must follow.
- Write procedures that turn the policy into steps — how backups run, how a restore is requested, and who declares an outage.
- Name an owner — a specific person or role — responsible for keeping the policy and procedures current.
- Disseminate both documents to the people who need them, not just file them away.
- Review and update on a set schedule (for example, yearly) and after any major event — a bad outage, a new server, or an audit finding.
Framework mapping
- NIST CSF 2.0 — GV.PO-01 — Policy for managing cybersecurity risks is established, communicated, and enforced
How to move it toward Implemented
- Draft a one- to two-page contingency planning policy for this server: purpose, scope (which systems), roles, and a review cadence. Save it as a dated document.
- Write a matching procedures file that points at the real commands on this box — where backups are written, how to trigger a restore, and who to call.
- Record the named owner and the next review date somewhere durable (the asset record or a tracked file) so the schedule does not quietly lapse.
- Attach the policy and procedures as hardening evidence on the asset, naming
CP-1in the Requirement field — that moves it from ‘To assess’ toward ‘Completed’.