Skip to content

Evidence request lists

NIST Special Publication 800-34 Revision 1, Contingency Planning Guide for Federal Information Systems

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Business Impact Analysis

NISTSP34-2
Business Impact Analysis (BIA): Critical Resources, Recovery Priorities

Conduct Business Impact Analysis per NIST SP 800-34 Rev 1 Section 3.2 + Appendix B (Sample BIA Template). BIA identifies and prioritises information systems and components critical to supporting the organisations mission/business processes. BIA must (a) determine mission/business processes and recovery criticality per Section 3.2.1: identify the systems supporting each mission/business process + the impact of disruption + recovery time objective (RTO) + recovery point objective (RPO) + maximum tolerable downtime (MTD) per process, (b) identify resource requirements per Section 3.2.2: hardware + software + data + facilities + personnel + supplier dependencies + external service providers + critical records + telecommunications, (c) identify system resource recovery priorities per Section 3.2.3: order systems by criticality with documented rationale + alignment with FIPS 199 security categ

Artefacts an auditor will ask for
  • BIA per system aligned to Appendix B template with RTO + RPO + MTD per mission/business process
  • resource requirements inventory (hardware + software + data + facilities + personnel + suppliers + telecom + records)
  • system recovery prioritisation aligned with FIPS 199 + organisational risk tolerance
  • annual BIA review evidence with mission/business owner sign-off
Where this commonly fails
  • BIA conducted by IT without mission/business owner engagement
  • RTO/RPO set without exercise verification
  • BIA last updated more than 12 months ago despite significant business change

Contingency Planning Policy and Programme

NISTSP34-1
Contingency Planning Policy, Programme, and Plan Coordination

Establish a contingency planning policy and programme per NIST SP 800-34 Rev 1 Section 3.1 (Develop the Contingency Planning Policy Statement). Policy must define (a) scope and applicability across federal information systems + supporting infrastructure + dependencies, (b) roles and responsibilities aligned with NIST RMF (Authorising Official + System Owner + Information System Security Officer + Information System Contingency Plan Coordinator + Business Continuity Coordinator + Disaster Recovery Coordinator), (c) resource requirements + training requirements + exercise and testing schedules + plan maintenance schedule, (d) integration with other contingency-related plans per NIST SP 800-34 Rev 1 Section 2.2 covering Continuity of Operations Plan (COOP) + Business Continuity Plan (BCP) + Business Recovery Plan (BRP) + Incident Response Plan (IRP) + Disaster Recovery Plan (DRP) + Crisis C

Artefacts an auditor will ask for
  • approved contingency planning policy with scope + roles + resources + training + testing + maintenance
  • plan coordination matrix per SP 800-34 Section 2.2 covering COOP + BCP + BRP + IRP + DRP + Crisis Comms + ISCP + CIRP + OEP
  • annual policy review evidence + revision evidence after significant change
Where this commonly fails
  • multiple plans without coordination matrix producing conflicts in real event
  • policy approved but resources not allocated for implementation
  • no annual review evidence

ISCP Development

NISTSP34-4
Information System Contingency Plan (ISCP) Development

Develop the Information System Contingency Plan (ISCP) per NIST SP 800-34 Rev 1 Section 3.5 + Appendix A (Sample ISCP Template). ISCP must include (a) Supporting Information per Section 3.5.1: introduction + concept of operations + system description and architecture + ISCP overview, (b) Activation and Notification Phase per Section 3.5.2: activation criteria + notification procedures + outage assessment criteria + decision authority for plan activation, (c) Recovery Phase per Section 3.5.3: sequence of recovery activities + execution priorities + recovery procedures per resource + escalation paths + status reporting + decision authority for recovery decisions, (d) Reconstitution Phase per Section 3.5.4: validation of system functionality + concurrent processing + system testing + transition to normal operations + lessons-learned capture + ISCP update triggers, (e) Plan Appendices per Se

Artefacts an auditor will ask for
  • complete ISCP per Appendix A template covering Supporting Info + Activation/Notification + Recovery + Reconstitution + Appendices
  • plan aligned to FIPS 199 impact level per Appendix F
  • plan ownership by execution personnel + quarterly walkthrough evidence
  • ISCP integration with system architecture documentation
Where this commonly fails
  • plan exists but personnel who execute it are unfamiliar with content
  • plan template followed but content generic not system-specific
  • reconstitution phase undefined or unrealistic

Impact-Aligned Recovery + RMF Integration

NISTSP34-8
Recovery Capability by Impact Level, RTO/RPO, and Integration with NIST RMF

Operate recovery capability aligned with FIPS 199 impact level + NIST RMF integration per NIST SP 800-34 Rev 1 Appendix F (Sample Plans per Impact Level) + Chapter 4 (Information System Contingency Plan Development). Recovery capability per impact level: (a) Low impact systems per Section F.2: minimum capability covering tape backup + cold site or commercial recovery + tabletop exercise annually + plan walkthrough annually, (b) Moderate impact systems per Section F.3: enhanced capability covering more frequent backups + warm site + functional test annually + technical recovery exercise annually, (c) High impact systems per Section F.4: full capability covering real-time replication + hot site or mirrored site + multiple geographic regions + full-scale exercise annually + continuous improvement programme. RTO and RPO must be set per system aligned with BIA mission criticality + verified b

Artefacts an auditor will ask for
  • recovery capability per FIPS 199 impact level matching Appendix F minimums
  • RTO + RPO commitments per system with exercise verification evidence
  • RMF Authorize step evidence using current ISCP + exercise + maintenance outputs
  • alignment with NIST SP 800-53 Rev 5 CP family controls (CP-1 through CP-13)
Where this commonly fails
  • High-impact system with Low-impact recovery capability
  • RTO + RPO commitments unverified by exercise
  • ISCP not part of RMF Authorize evidence

Plan Maintenance

NISTSP34-6
Plan Maintenance: Updates, Approval, Distribution, Configuration Control

Maintain the plan per NIST SP 800-34 Rev 1 Section 3.7. Maintenance must (a) update plan content on triggers including system change + operational change + threat change + personnel change + lessons-learned + regulatory change, (b) review the plan at minimum annually even without trigger, (c) apply version control + change tracking + distribution management + access control to plan documentation including printed and electronic copies, (d) document plan approval per Section 3.7.1 by senior management + designated approving authority + with documented approval date + scope + signature, (e) distribute plan per Section 3.7.2 to all personnel with responsibilities + maintain distribution list + recall and replace obsolete versions + protect plan from unauthorised access (the plan itself contains information valuable to adversaries), (f) integrate plan updates with system change management +

Artefacts an auditor will ask for
  • plan update log with trigger events + change description + approver + distribution
  • annual review evidence even without trigger
  • version control + change tracking + distribution list + recall of obsolete versions
  • plan classification + access control + protection from unauthorised access
Where this commonly fails
  • plan last updated more than 12 months ago despite system or organisational change
  • plan distribution list out of date with personnel turnover
  • plan stored without access control allowing unauthorised inspection

Preventive Controls and Recovery Strategies

NISTSP34-3
Preventive Controls and Recovery Strategies: Backup, Alternate Sites, Equipment

Identify preventive controls and develop recovery strategies per NIST SP 800-34 Rev 1 Section 3.3 (Identify Preventive Controls) + Section 3.4 (Create Contingency Strategies). Preventive controls per Section 3.3 reduce the effect of system disruptions through technical controls (appropriately sized UPS + generator + environmental controls + fire suppression + redundant components + redundant networking) + procedural controls (operations and maintenance + change management + capacity planning + monitoring) + management controls (risk management + security policies). Recovery strategies per Section 3.4 covering (a) backup strategy per Section 3.4.1: backup frequency aligned with RPO + media types + on-site/off-site rotation + encryption + retention + restore testing + secure disposal, (b) alternate sites per Section 3.4.2: cold site + warm site + hot site + mobile site + mirrored site sele

Artefacts an auditor will ask for
  • preventive controls inventory + verification (UPS + generator + environment + fire + redundancy + monitoring)
  • backup strategy documented with frequency + media + rotation + encryption + retention + restore testing evidence
  • alternate site selection record with cold/warm/hot/mobile/mirrored rationale + RTO + cost + threat coverage
  • equipment replacement strategy + vendor agreements + spares inventory + lead-time analysis
Where this commonly fails
  • alternate site selected on cost alone without threat-coverage rationale
  • backup encryption absent or restore never tested
  • preventive controls deployed but verification absent (UPS battery life not tested)

Telecommunications and Third-Party Contingency

NISTSP34-7
Telecommunications and External Service Resilience, Cloud and Third-Party Contingency

Address telecommunications and external service resilience + cloud and third-party contingency per NIST SP 800-34 Rev 1 Section 3.4.5 + Section 4 + modern cloud-era guidance. Telecommunications services resilience per Section 3.4.5 + Appendix E (Continuity Considerations for Telecom Services): (a) diverse providers + diverse circuits + diverse entries into facility + monitoring + automatic failover + tested manual failover, (b) Government Emergency Telecommunications Service (GETS) + Wireless Priority Service (WPS) registration where applicable, (c) emergency communications equipment + satellite phone + radio + emergency contact procedures. Cloud and third-party service contingency: (a) cloud provider Service Level Agreements covering availability + recovery commitments + provider contingency capability per region + cross-region replication + provider transparency on incidents + provider

Artefacts an auditor will ask for
  • telecommunications resilience evidence (diverse providers + circuits + entries + failover testing + GETS/WPS registration where applicable)
  • cloud provider SLA + contingency capability + cross-region replication architecture + exit and portability plan
  • third-party SOC 2 / ISO 22301 BCP attestation review + provider exercise output review
  • multi-region or multi-cloud architecture decision record where applicable
Where this commonly fails
  • single telecom circuit producing single-point failure
  • cloud provider SLA accepted at vendor default without contingency capability review
  • no exit/portability plan despite consumer regulation demanding it

Testing, Training, Exercises

NISTSP34-5
Plan Testing, Training, and Exercises (TTE)

Conduct Plan Testing, Training, and Exercises (TTE) per NIST SP 800-34 Rev 1 Section 3.6 + Appendix C (TTE Best Practices) + NIST SP 800-84 Guide to Test, Training, and Exercise Programs. Testing per Section 3.6.1 must (a) verify the plan documented procedures work as designed including notification + activation + system recovery + reconstitution + escalation + decision authority, (b) include functional tests (technical recovery of system components in a test environment) + tabletop exercises (discussion-based walkthroughs) + drills + full-scale exercises depending on impact level + organisational maturity + regulatory requirements per Appendix F. Training per Section 3.6.2 must (a) provide initial training for personnel with ISCP responsibilities covering plan content + procedures + contact information + decision authority + tools, (b) refresh training annually + after significant plan

Artefacts an auditor will ask for
  • TTE schedule per impact level (Low annual tabletop + Moderate annual technical + High annual full-functional)
  • training records per role with initial + refresher + change-trigger evidence
  • after-action reports per exercise with findings + recommendations + closure tracking
  • exercise observation + facilitation notes + lessons learned fed back into plan updates
Where this commonly fails
  • exercises conducted but no after-action report or findings not closed
  • training records absent or only for initial onboarding
  • tabletop exercise mistaken for technical recovery test
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the NIST Special Publication 800-34 Revision 1, Contingency Planning Guide for Federal Information Systems framework page.