Attachment-G4-ACF_Contingency Plan.docx_V1.0.docx
DOCX document 112 KB Posted
- Attached to
- Legal Services for Unaccompanied Alien Children (UAC) Federal contract opportunity
- Solicitation number
- 75P00126R00003
- Issued by
- Not on record
About this file
This is an ACF Contingency Plan template (Version 1.0, dated 6/26/25) designed to help resume critical system operations following emergencies such as fires, power outages, tornadoes, hurricanes, floods, earthquakes, or civil disturbances. The plan follows NIST SP 800-34 guidelines and is classified as Controlled Unclassified Information (CUI). The document is a blank template with placeholder fields for organizations to customize for their specific systems.
The plan is structured around four primary sections: Introduction and Purpose, Roles & Responsibilities, Contingency Plan Execution, and Approval and Authorization. The execution section contains three operational phases—Activation, Recovery, and Reconstitution. Activation is triggered when system outage exceeds the Recovery Time Objective (RTO) or facility damage prevents access within the RTO window, with defined notification procedures for key personnel. Recovery procedures outline steps to restore system functionality from backup media, with escalation protocols for leadership notification. Reconstitution includes data validation testing, system functionality testing, recovery declaration, user notification, cleanup procedures, offsite data storage return, full system backup scheduling, and formal deactivation. Supporting appendices address vendor contact information, alternate processing procedures, annual testing and maintenance schedules, and associated contingency plans for related systems. The template requires completion of system-specific details including impact level per FIPS 199, data center information, RTO in hours, responsible personnel contacts, and detailed recovery and validation procedures.
View the file
Other files for this federal contract opportunity
Show all 50
Legal Services for Unaccompanied Alien Children (UAC) has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Enter System Name ACF
Contingency Plan Enter System Name
Version 1.0 Dated: 6/26/25
Table of Contents
| 1. Introduction and Purpose | 3 |
| 1.2 Assumptions and Exclusions | 3 |
| 1.3 System Overview | 4 |
| 2. Roles & Responsibilities | 5 |
| 3. Contingency Plan Execution | 6 |
| 3.1 Activation | 6 |
| 3.1.1 Activation Criteria | 6 |
| 3.1.2 Activation & Notification Procedure | 6 |
| 3.2 Recovery | 7 |
| 3.2.1 Recovery Procedures | 7 |
| 3.2.2 Recovery Document Location | 7 |
| 3.2.2 Escalation Procedures | 7 |
| 3.3 Reconstitution | 7 |
| 3.3.1 Validation Testing | 7 |
| 3.3.2 Validation Functionality Testing | 8 |
| 3.3.3 Recovery Declaration | 8 |
| 3.3.4 Notification (users) | 8 |
| 3.3.5 Cleanup | 9 |
| 3.3.6 Offsite Data Storage | 9 |
| 3.3.7 Data Backup | 9 |
| 4. Approval and Authorization | 10 |
| Appendix A. Vendor Contact List | 11 |
| Appendix B. Alternate Processing Procedures | 12 |
| Appendix C. Test and Maintenance Schedule | 13 |
| Appendix D. Associated Plans and Procedures | 14 |
| Document Revision History | 15 |
1. Introduction and Purpose This Contingency Plan follows NIST SP 800-34 guidelines and outlines the necessary materials for meeting federal security standards. The plan is designed to help quickly resume critical system operations after emergencies like fires, power outages, tornadoes, hurricanes, floods, earthquakes, or civil disturbances. This document’s information is proprietary and classified as Controlled Unclassified Information (CUI).
1.2 Assumptions and Exclusions
Identify the assumptions and exclusions that apply to this Plan. Add additional assumptions and exclusions as applicable.
Table 1. Assumptions and Exclusions
Assumptions and Exclusions
| What is the system’s impact level, per FIPS 199? |
| Select level |
| Are alternative processing sites and offsite storage required for this system? |
| Select answer |
| Have key personnel been trained on an emergency response plan? |
| Select answer |
| Are key personnel available to activate this Plan? |
| Select answer |
| What is the name of the Data Center? |
| Click or tap here to enter text. |
| Can the Data Center be physically accessed? |
| Select answer |
| What is the Recovery Time Objective (RTO), in hours? |
| Click or tap here to enter text. |
| Will the system still be inoperable and inaccessible after the RTO? |
| Select answer |
Enter additional assumptions or exclusions
The Contingency Plan does not apply to the following situations:
· Short-term disruptions lasting less than Enter RTO number hours.
· Overall recovery and continuity of business operations.
· Emergency evacuation of personnel.
1.3 System Overview
Leverage the information from the System Security Plan (SSP) to provide a general description of the system architecture and functionality. Indicate the operating environment, physical location, general location of users, and partnerships with external organizations/systems. Include information regarding other critical technical recovery considerations, such as backup procedures.
Enter system description
Provide a system architecture diagram.
2. Roles & Responsibilities Identify all people responsible for activating, executing, and supporting the contingency plan. Add additional rows as needed Table 2. Contingency Plan Contact List
| Role |
| Name |
| Phone |
| Responsibility Note |
3. Contingency Plan Execution Describe the phases of contingency plan execution in the sections below.
3.1 Activation
Define the initial actions to detect and assess damage caused by a disruption to the system.
3.1.1 Activation Criteria
Confirm the following criteria that will trigger the activation of the Contingency Plan:
· The system outage indicates the system will be down for more than RTO number hours.
· The facility housing is damaged and may not be available within RTO number hours.
Add additional criteria as applicable
3.1.2 Activation & Notification Procedure
Identify the persons with the power to activate the Contingency Plan if one or more activation criteria are met.
Describe the established notification procedures. Include the person who makes the initial notification, the sequence in which personnel are notified, and the notification method.
Table 3. Notification Sequence
| Order Notified |
| Person Notified |
| Notified by |
| Notification method |
| Additional info |
3.2 Recovery
The system should be functional and capable of performing the functions identified in Section 1.3 of this Plan after recovery is complete.
3.2.1 Recovery Procedures
Outline the steps to recover the system from backup media. Identify which teams or people are responsible for each step. If detailed instructions with specific keystrokes are needed, they should be included in an appendix; please include a link to that appendix section.
Enter recovery steps
3.2.2 Recovery Document Location
Provide a link to the location where recovery documents are stored.
Enter recovery documents location
3.2.2 Escalation Procedures
Describe the procedures for sending escalation notices during recovery efforts. Include how leadership, system owners, and users will be informed and updated. Identify who is responsible for escalation notifications.
Enter escalation procedures
3.3 Reconstitution
Bring the system back to normal operations after recovery is complete.
3.3.1 Validation Testing
Outline the steps to verify and validate that recovered data is accurate and current. Identify teams or individuals responsible for each step.
Table 4. Data Verification Testing
| Verification Step |
| Responsible Team or Individual |
Table 6. Data Validation Test Plan
| Procedure |
| Expected Results |
| Actual Results |
| Success? |
| Performed by: |
3.3.2 Validation Functionality Testing
Outline the steps to verify that the recovered system is operating correctly. Identify teams or individuals responsible for each step.
Table 6. System Validation Test Plan
| Procedure |
| Expected Results |
| Actual Results |
| Success? |
| Performed by: |
3.3.3 Recovery Declaration
Once testing and validation are done, the Enter name of designated authority officially announces that recovery efforts are finished and the system operates normally. The Contingency Plan Coordinator informs the business and technical points of contact.
3.3.4 Notification (users)
On return to normal system operations, system users are notified by Enter role using Enter notification procedures.
3.3.5 Cleanup
Describe cleanup procedures for the system, including locations for manuals and documents, and how backup or installation media will be returned to their original location.
Enter cleanup procedures
3.3.6 Offsite Data Storage
Describe how retrieved backup or installation media will be returned to its off-site data storage location. Include details on proper logging and packaging, transportation preparation, validation of secure storage, etc.
Enter offsite data storage details
3.3.7 Data Backup
Describe procedures for ensuring a full system backup within a reasonable time frame, ideally at the next scheduled backup period.
Enter data backup procedures
3.3.8 Deactivation
After all activities are finished and documentation is updated, the Enter name of designated authority officially ends the Contingency Plan recovery process, and all business and technical points of contact are notified.
4. Approval and Authorization Contingency Plan Completion Date: Select date The information contained in this System’s Contingency Plan has been reviewed and approved by the following authority.
Enter System Owner name Digital Signature – Date
Appendix A. Vendor Contact List List contact information for all maintenance and support vendors.
Table 7. Vendor Contact List
| Vendor Name |
| Contact Name |
| Emergency Phone Number |
| Contractual Response Times |
| Contractual Onsite Times |
Appendix B. Alternate Processing Procedures Please describe alternate manual or technical processing procedures that would allow the affected business unit to continue processing information typically done by the affected system.
Enter procedures
Appendix C. Test and Maintenance Schedule Provide the yearly schedule for testing the system.
Table 8. Yearly Test and Maintenance Schedule
| Step |
| Due Date |
| Responsible Party |
| Date Scheduled |
| Date Held |
Appendix D. Associated Plans and Procedures Please identify contingency plans for other related systems. Include the most current version, location, and primary point of contact for each Contingency Plan.
Enter plans and procedures
Document Revision History
| Date |
| Version |
| Comments |
Version 1.0 Contingency Plan 1 image2.png image1.png image3.png
File details come from the government source that posted it. Updated .