{"licence":{"name":"CC BY-SA 4.0","spdx":"CC-BY-SA-4.0","url":"https://creativecommons.org/licenses/by-sa/4.0/","attribution":"Atlas, a bilingual technical dictionary (https://cmaintz.github.io/tech-atlas/)"},"id":"security/contingency-plan","url":{"en":"https://cmaintz.github.io/tech-atlas/en/terms/security/contingency-plan/","da":"https://cmaintz.github.io/tech-atlas/da/terms/security/contingency-plan/"},"term":{"en":"Contingency plan","da":"Beredskabsplan"},"aka":{"en":[],"da":[]},"domain":["security"],"cluster":"incident-response","layer":"governance","status":"current","summary":{"en":"A written, approved plan for how the organisation reacts when something goes wrong - who does what, and in which order.","da":"En nedskrevet og godkendt plan for, hvordan organisationen reagerer, når noget går galt - hvem gør hvad og i hvilken rækkefølge."},"body":{"formal":{"en":"The umbrella document that sets roles, decision powers, escalation routes and first actions for incidents, and ties together the BCP, the DRP and the communication plan.","da":"Det overordnede dokument, der fastlægger roller, beslutningskompetence, hvem der skal inddrages hvornår, og de første handlinger ved hændelser, og som samler BCP, DRP og kommunikationsplan."},"plain":{"en":"Like the fire instructions on the back of a hotel room door, but written for the whole organisation.","da":"Ligesom skiltet bag på en hoteldør, der viser, hvad man gør ved brand - bare for hele organisationen."},"inPractice":{"en":"When the control system for a town's drinking water goes dark on a Sunday, the operations manager opens the plan, calls the three people on the list and works through the first page of the checklist.","da":"Da styringssystemet på et vandværk går ned en søndag, åbner driftslederen planen, ringer til de tre personer på listen og følger første side af tjeklisten."},"whyItMatters":{"en":"In a crisis people panic and forget, so decisions made calmly in advance are what keep the response orderly.","da":"I en krise går folk i panik og glemmer ting, så beslutninger truffet i ro og mag på forhånd er det, der holder reaktionen ordnet."}},"deepDive":{"en":"The term is used at two levels, and the difference matters when reading standards. In NIST SP 800-34 Rev. 1, \"contingency planning\" is the umbrella discipline, and the information system contingency plan (ISCP) is a specific plan for recovering one system. The same guide lists neighbouring plan types with their own scope: business continuity plan, continuity of operations plan, crisis communications plan, critical infrastructure protection plan, cyber incident response plan, disaster recovery plan and occupant emergency plan. In Danish practice, \"beredskabsplan\" usually refers to the top-level document that binds these together, so a Danish beredskabsplan often corresponds to the NIST umbrella rather than to a single ISCP.\n\nNIST SP 800-34 describes a seven-step process: develop the contingency planning policy; conduct the business impact analysis; identify preventive controls; create contingency strategies; develop the plan; plan testing, training and exercises; and plan maintenance. The ISCP itself is structured in three phases after the supporting information: activation and notification, in which the outage is assessed and the plan formally invoked; recovery, in which operations are restored in the documented order; and reconstitution, in which the system is validated, tested, returned to normal operation and the plan deactivated. In NIST SP 800-53 Rev. 5 the same ground is covered by the CP control family, notably CP-2 Contingency Plan, CP-4 testing, CP-9 system backup and CP-10 system recovery and reconstitution.\n\nThe umbrella plan's own content is mostly organisational: activation criteria and who may declare an incident or a crisis, the response organisation with named roles and deputies, decision mandates (for example who may disconnect the organisation from the internet or shut down production), escalation and contact lists including suppliers, insurer, lawyers and authorities, and references to the subordinate plans and playbooks. Version control, an owner and a review cycle are part of the plan, and copies must be available offline, since the document server may be among the systems that are down.\n\nNIS2 Article 21(2) requires incident handling and business continuity measures, and in Danish public administration the obligation to plan for continuity of critical functions has a longer history under the national emergency management framework. The most frequent weaknesses found in exercises are outdated contact lists, missing deputies, unclear decision authority between IT and management, and subordinate plans that assume the same infrastructure the incident has taken away. A contingency plan is not the same as incident response: incident response is the process of handling a security event, while the contingency plan is the prepared framework that includes incident response alongside continuity, recovery and communication.","da":"Begrebet bruges på to niveauer, og forskellen betyder noget, når man læser standarder. I NIST SP 800-34 Rev. 1 er \"contingency planning\" den overordnede disciplin, mens information system contingency plan (ISCP) er en bestemt plan for at genoprette ét system. Samme vejledning nævner tilgrænsende plantyper med hvert sit omfang: business continuity plan, continuity of operations plan, krisekommunikationsplan, plan for beskyttelse af kritisk infrastruktur, plan for håndtering af cyberhændelser, disaster recovery-plan og evakueringsplan for bygningen. I dansk praksis betegner \"beredskabsplan\" oftest det overordnede dokument, der binder dem sammen, så en dansk beredskabsplan svarer ofte til NIST's paraply og ikke til en enkelt ISCP.\n\nNIST SP 800-34 beskriver en proces i syv trin: udarbejd en politik for beredskabsplanlægning; gennemfør konsekvensanalysen; identificér forebyggende kontroller; udarbejd beredskabsstrategier; skriv planen; planlæg test, træning og øvelser; og planlæg vedligeholdelse. Selve ISCP'en er efter baggrundsoplysningerne bygget op i tre faser: aktivering og varsling, hvor nedbruddet vurderes, og planen formelt sættes i værk; genopretning, hvor driften genetableres i den dokumenterede rækkefølge; og rekonstitution, hvor systemet valideres, testes og sættes tilbage i normal drift, og planen deaktiveres. I NIST SP 800-53 Rev. 5 dækkes samme område af kontrolfamilien CP, især CP-2 Contingency Plan, CP-4 test, CP-9 backup af systemet og CP-10 genopretning og rekonstitution af systemet.\n\nDen overordnede plans eget indhold er mest organisatorisk: kriterier for aktivering og for, hvem der må erklære en hændelse eller en krise, beredskabsorganisationen med navngivne roller og stedfortrædere, beslutningsmandater (fx hvem der må koble organisationen fra internettet eller standse produktionen), eskalerings- og kontaktlister inklusive leverandører, forsikringsselskab, advokater og myndigheder samt henvisninger til de underliggende planer og playbooks. Versionsstyring, en ejer og en fast revisionscyklus er en del af planen, og kopier skal være tilgængelige offline, fordi dokumentserveren kan være blandt de systemer, der er nede.\n\nNIS2 artikel 21, stk. 2, kræver foranstaltninger til hændelseshåndtering og driftskontinuitet, og i den danske offentlige forvaltning har pligten til at planlægge for videreførelse af kritiske funktioner en længere historie i det nationale beredskabssystem. De hyppigste svagheder, øvelser afslører, er forældede kontaktlister, manglende stedfortrædere, uklar beslutningskompetence mellem IT og ledelse og underliggende planer, der forudsætter den samme infrastruktur, som hændelsen har taget væk. En beredskabsplan er ikke det samme som hændelseshåndtering: hændelseshåndtering er processen med at håndtere en sikkerhedshændelse, mens beredskabsplanen er den forberedte ramme, der rummer hændelseshåndteringen sammen med kontinuitet, genopretning og kommunikation."},"edges":[{"type":"requires","to":"security/incident-response","confidence":"high","strength":"normal"},{"type":"requires","to":"security/business-impact-analysis","confidence":"high","strength":"normal"},{"type":"requires","to":"security/recovery-objectives","confidence":"high","strength":"normal"},{"type":"used-with","to":"security/management-responsibility","confidence":"high","strength":"normal"}],"depth":5,"sources":[{"title":"Cyber Security Fast Track - Ordliste","tier":"course-material"},{"title":"NIST SP 800-34 Rev. 1","tier":"standard"}],"draft":true}