Frameworks / CIS Controls v8 / CIS-11.1 CIS Controls v8
CIS Control 11: Data Recovery
CIS Controls v8 CIS-11.1: Establish and Maintain a Data Recovery Process Set up and keep a process for recovering data that defines what recovery covers, the order of recovery priorities, and how backup data is kept secure. Revisit the documentation each year, or sooner when a major change in the enterprise could affect this Safeguard.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 94 controls across 27 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
7.5.3 Control of documented information 8.2.2 Business impact analysis 8.3 Business continuity strategies and solutions 8.3.1 General 8.3.2 Identification of strategies and solutions 8.3.5 Implementation of solutions 8.4.1 General 8.4.4 Business continuity plans 8.4.5 Recovery CP-1 Policy and Procedures CP-10 System Recovery and Reconstitution CP-10(2) System Recovery and Reconstitution | Transaction Recovery (CP-10(2)) CP-2 Contingency Plan CP-2(3) Resume Mission and Business Functions CP-9 System Backup IR-2 Incident Response Training IR-3 Incident Response Testing CP-1 Policy and Procedures CP-10 System Recovery and Reconstitution CP-10(2) System Recovery and Reconstitution | Transaction Recovery (CP-10(2)) CP-2 Contingency Plan CP-2(3) Resume Mission and Business Functions CP-9 System Backup IR-2 Incident Response Training IR-3 Incident Response Testing NIST-CSF-ID.IM-04 Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved NIST-CSF-PR.DS-11 Backups of data are created, protected, maintained, and tested NIST-CSF-PR.IR-03 Mechanisms are implemented to achieve resilience requirements in normal and adverse situations NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process NIST-CSF-RC.RP-02 Recovery actions are selected, scoped, prioritized, and performed NIST-CSF-RC.RP-03 The integrity of backups and other restoration assets is verified before using them for restoration NIST-CSF-RC.RP-04 Critical mission functions and cybersecurity risk management are considered to establish post-incident operational norms NIST-CSF-RC.RP-06 The end of incident recovery is declared based on criteria, and incident-related documentation is completed 5.24 Information security incident management planning and preparation 5.29 Information security during disruption 5.30 ICT readiness for business continuity 5.37 Documented operating procedures 8.13 Information backup CFTC-SS-11 Testing and Review of Business Continuity and Disaster Recovery Capabilities CFTC-SS-22 Business Continuity and Disaster Recovery Planning Category CFTC-SS-37 Protection of Swap Data Repository Data CFTC-SS-8 Business Continuity and Disaster Recovery Plan and Resources ASD37-34 Regular backups (Essential) ASD37-35 Business continuity and disaster recovery plans (Very Good) ASD37-36 System recovery capabilities (Very Good) ASBv3-BR-3 Monitor backups ASBv3-GS-8 Define and implement backup and recovery strategy BR-1 Ensure regular automated backups 5.29 Information security during disruption 5.30 ICT readiness for business continuity 8.13 Information backup 6.14 Information security aspects of business continuity management 6.14.1 Information security continuity 6.9.3 Backup 12.10.1 12.10.1 Incident response plan ready for activation 12.10.2 12.10.2 Annual review and testing of the incident response plan 12.3.1 12.3.1 Targeted risk analysis for flexible-frequency requirements SOC2-A1.2 A1.2 Environmental protection, backup and recovery infrastructure SOC2-A1.3 A1.3 Testing recovery plan procedures SOC2-CC9.1 CC9.1 Mitigating risks of business disruption ISM-1547 Data backup processes and procedures ISM-1548 Data restoration processes and procedures E8-BACKUP-ML1 Regular Backups (ML1) ANSSI-HYG-37 Define and Apply a Backup Policy for Critical Components CPS230-26 Critical Operations Register, Continuity Plan and Activation AEO-12 Crisis Management and Incident Recovery 11.1 Establish and Maintain a Data Recovery Process Art.21.2.c Business continuity, backup management, disaster recovery and crisis management Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in CIS Control 11: Data Recovery You are reading one control. How much of CIS Controls v8 have you already done? CIS Controls v8 CIS-11.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of CIS Controls v8 your existing evidence covers. Hold ISO 27001:2022 and 102 of 153 CIS Controls v8 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 240 were rejected on the ISO 27001:2022 pair alone.
Query this from an agent The graph holds this control, the 94 it maps to, and the evidence behind each claim, over MCP and REST.