This document provides guidance for developing effective IT contingency plans. It outlines a seven-step contingency planning process that includes developing policy, conducting business impact analysis, identifying preventive controls and recovery strategies, developing and testing a contingency plan, and maintaining the plan. It also discusses considerations for contingency planning for different types of IT systems like desktops, servers, web sites, networks and mainframes. The goal is to help organizations establish thorough plans and procedures to enable quick and effective IT system recovery following a disruption.