Business Continuity
BCP DR Concepts - Types of BCP Plans
- Details
- Written by: Robin Basham
- Parent Category: Services
- Category: Business Continuity
Article Index
|
Plan |
Purpose |
Scope |
Plan Relationship |
|
Business Continuity Plan |
Provides procedures for sustaining mission/business operations while recovering from a significant disruption |
Addresses mission / business processes at a lower or expanded level from COOP MEFs |
Mission/business process focused plan that may be activated in coordination with a COOP plan to sustain non-MEFs. |
|
Continuity of Operations (COOP) Plan |
Provides procedures and guidance to sustain an organization’s MEFs at an alternate site for up to 30 days; mandated by federal directives. |
Addresses MEFs at a facility; information systems are addressed based only on their support of the mission essential functions. |
MEF focused plan that may also activate several business unit-level BCPs, ISCPs, or DRPs, as appropriate. |
|
Crisis Communications Plan |
Provides procedures for disseminating internal and external communications; means to provide critical status information and control rumors. |
Addresses communications with personnel and the public; not information system- focused. |
Incident-based plan often activated with a COOP or BCP, but may be used alone during a public exposure event. |
|
Critical Infrastructure Protection (CIP) Plan |
Provides policies and procedures for protection of national critical infrastructure components, as defined in the National Infrastructure Protection Plan. |
Addresses critical infrastructure components that are supported or operated by an agency or organization. |
Risk management plan that supports COOP plans for organizations with critical infrastructure and key resource assets. |
|
Cyber Incident Response Plan |
Provides procedures for mitigating and correcting a cyberattack, such as a virus, worm, or Trojan horse. |
Addresses mitigation and isolation of affected systems, cleanup, and minimizing loss of information. |
Information system- focused plan that may activate an ISCP or DRP, depending on the extent of the attack. |
|
Disaster Recovery Plan (DRP) |
Provides procedures for relocating information systems operations to an alternate location. |
Activated after major system disruptions with long-term effects. |
Information system- focused plan that activates one or more ISCPs for recovery of individual systems. |
|
Information System Contingency Plan (ISCP) |
Provides procedures and capabilities for recovering an information system. |
Addresses single information system recovery at the current or, if appropriate alternate location. |
Information system- focused plan that may be activated independent from other plans or as part of a larger recovery effort coordinated with a DRP, COOP, and/or BCP. |
|
Occupant Emergency Plan (OEP) |
Provides coordinated procedures for minimizing loss of life or injury and protecting property damage in response to a physical threat. |
Focuses on personnel and property particular to the specific facility; not mission/business process or information system based. |
The incident-based plan that is initiated immediately after an event, preceding a COOP or DRP activation. |
- Hits: 782

Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics