I had an opportunity to review the draft of the upcoming revision 1 to Federal Continuity Directive 1 (FCD-1). I had several issues with it. It talks about about “establishing contingency plans for the performance of essential functions.” Unfortunately this contradicts SP 800-34 which says “An Information System Contingency Plan (ISCP) Provides procedures and capabilities for recovery an information system.”
Just to clarify - Until this draft, the government has used the term “contingency plan” to denote the policies and procedures for the recovery of a single system. “COOP Plan” has been used as the policies and procedures for recovering Primary Mission Essential Functions (PMEFs) and Mission Essential Functions (MEFs).
There are several other instances where the drafters of this revision crossed terms as used in other publications, particularly the NIST Special Publications. I’d like to see more consistency across publications to reduce confusion. Continue reading