Understanding SP 800-34 and the related continuity plans.
NIST SP 800-34 (revision 1) was approved and signed this past May. This revision provides far more guidance for contingency plan development than its predecessor.
When developing an Information System Contingency Plan (ISCP) it is critical to remember that the purpose of this type of plan is to organize the recovery policies, requirements, and procedures for a single system into a single easy to follow document. Referencing other documents, spreadsheets, diagrams, etc., will make your plan difficult to use and, if the referenced documents reside on your network, they may not be available when you need them. Your ISCP should be easy to read, break down all tasks into manageable and traceable steps, and contain all of the information that you need to implement it.
To continue reading this whitepaper, including details and development of the ISCP,
click here.
In the next issue we will look at incident response and how to make your IRP dovetail into your recovery capability.
To find out more information on Lunarline’s extensive experience in identifying, developing and implementing recovery strategies,
click here.
Like this:
Be the first to like this post.