Executive summary
Infrastructure resilience is the ability to anticipate disruption, continue the most important service functions, recover within an acceptable window, and adapt after failure. NIST SP 800-160 Volume 2 Rev. 1 frames cyber resiliency around the ability to anticipate, withstand, recover from, and adapt to adverse conditions.NIST SP 800-160 Vol. 2 Rev. 1 NIST contingency-planning guidance similarly begins with business-impact analysis, recovery requirements, plan development, testing, and maintenance.NIST SP 800-34 Rev. 1
The practical implication is simple: resilience should not be organized around a list of servers, generators, carriers, or vendors. It should be organized around services and their dependency chains. CISA's Infrastructure Dependency Primer emphasizes that energy, communications, IT, transportation, water, and other systems are interdependent; failure in one can disrupt several others.CISA Infrastructure Dependency Primer
This guide uses seven operating layers: service criticality, dependency mapping, resilient power and communications, recovery architecture, maintenance and spares, supplier/concentration risk, and exercises/evidence.