The organization must review provider contingency plans to ensure the plans meet organizational contingency requirements.

From Voice Video Policy Security Technical Implementation Guide

Part of SRG-POL-300420

Associated with: CCI-002842

VVSP-01-000087_rule The organization must review provider contingency plans to ensure the plans meet organizational contingency requirements.

Vulnerability discussion

This control applies to telecommunications services (data and voice) for primary and alternate processing and storage sites. Alternate telecommunications services reflect the continuity requirements in contingency plans to maintain essential missions/business functions despite the loss of primary telecommunications services. Organizations may specify different time periods for primary/alternate sites. Alternate telecommunications services include, for example, additional organizational or commercial ground-based circuits/lines or satellites in lieu of ground-based communications. Organizations consider factors such as availability, quality of service, and access when entering into alternate telecommunications agreements.Reviews of provider contingency plans consider the proprietary nature of such plans. In some situations, a summary of provider contingency plans may be sufficient evidence for organizations to satisfy the review requirement. Telecommunications service providers may also participate in ongoing disaster recovery exercises in coordination with the Department of Homeland Security and state and local governments. For Voice Video systems, contingency planning must also consider fire and emergency services (FES) requirements for life safety and Command and Control (C2) requirements mandating communications among top-level officials, especially during crisis conditions.

Check content

Review the contingency plan for the Voice Video system that addresses essential missions and business functions. Ensure the organization reviews provider contingency plans to ensure the plans meet organizational contingency requirements. These reviews must be documented and included with the contingency plan. If the organization does not review provider contingency plans to ensure the plans meet organizational contingency requirements, this is a finding. If the organization does not document the reviews in the contingency plan, this is a finding.

Fix text

Develop and document a contingency plan for the Voice Video system. As part of this plan, specify that the organization must review provider contingency plans to ensure the plans meet organizational contingency requirements.

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer