NIST 800-53 REV 5 • CONTINGENCY PLANNING

CP-2(3)Resume Mission and Business Functions

Plan for the resumption of {{ insert: param, cp-02.03_odp.01 }} mission and business functions within {{ insert: param, cp-02.03_odp.02 }} of contingency plan activation.

CMMC Practice Mapping

No direct CMMC mapping

NIST 800-171 Mapping

No direct NIST 800-171 mapping

Related Controls

No related controls listed

Supplemental Guidance

Organizations may choose to conduct contingency planning activities to resume mission and business functions as part of business continuity planning or as part of business impact analyses. Organizations prioritize the resumption of mission and business functions. The time period for resuming mission and business functions may be dependent on the severity and extent of the disruptions to the system and its supporting infrastructure.

Practitioner Notes

This enhancement requires your contingency plan to address resuming essential mission and business functions within a defined time period after a disruption.

Example 1: Define specific Recovery Time Objectives (RTOs) for each critical function — for example, email within 4 hours, ERP within 8 hours, file shares within 24 hours.

Example 2: Document the sequence of system restoration in your plan: restore Active Directory first, then DNS, then email, then business applications, ensuring dependencies are addressed in order.