CP-1—Contingency Planning Policy And Procedures
>Control Description
>Supplemental Guidance
This control is intended to produce the policy and procedures that are required for the effective implementation of selected security controls and control enhancements in the contingency planning family. The contingency planning policy and procedures are consistent with GC legislation and TBS policies, directive, and standards. Existing organizational policies and procedures may make additional specific policies and procedures unnecessary.
The contingency planning policy can be included as part of the general information security policy for the organization. Contingency planning procedures can be developed for the security program in general and for a particular information system, when required. The organizational risk management strategy is a key factor in the development of the contingency planning policy.
>Tailoring Guidance
This security control/enhancement is considered to be best practice. Consequently, inclusion in a departmental profile is strongly encouraged in most cases.
>Profile-Specific Parameters
(A) (B) frequency [at a frequency no longer than annually]
Ask AI
Configure your API key to use AI features.