NIST Cybersecurity Framework 2.0
PR - Protect

NIST Cybersecurity Framework 2.0 NIST-CSF-PR.DS-11: Backups of data are created, protected, maintained, and tested

Backups of data are created, protected, maintained, and tested. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 87 controls across 31 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

CIS Controls v8 · 8 controls

  • CIS-11.1 Establish and Maintain a Data Recovery Process
  • CIS-11.2 Perform Automated Backups
  • CIS-11.3 Protect Recovery Data
  • CIS-11.4 Establish and Maintain an Isolated Instance of Recovery Data
  • CIS-11.5 Test Data Recovery
  • CIS-15.7 Securely Decommission Service Providers
  • CIS-3.4 Enforce Data Retention
  • CIS-3.5 Securely Dispose of Data

NIST SP 800-53 Rev 5 · 8 controls

FedRAMP High · 7 controls

  • CP-10(2) System Recovery and Reconstitution | Transaction Recovery (CP-10(2))
  • CP-6 Alternate Storage Site
  • CP-6(1) Alternate Storage Site | Separation from Primary Site (CP-6(1))
  • CP-9 System Backup
  • CP-9(1) Testing for Reliability and Integrity
  • CP-9(8) System Backup | Cryptographic Protection (CP-9(8))
  • SI-12 Information Management and Retention

FedRAMP Moderate · 7 controls

  • CP-10(2) System Recovery and Reconstitution | Transaction Recovery (CP-10(2))
  • CP-6 Alternate Storage Site
  • CP-6(1) Alternate Storage Site | Separation from Primary Site (CP-6(1))
  • CP-9 System Backup
  • CP-9(1) Testing for Reliability and Integrity
  • CP-9(8) System Backup | Cryptographic Protection (CP-9(8))
  • SI-12 Information Management and Retention
  • ISM-1511 Backups aligned to business criticality
  • ISM-1515 Testing restoration to a common point
  • ISM-1707 Privileged accounts prevented from altering backups
  • ISM-1811 Secure and resilient retention of backups

C5 (Germany) · 4 controls

  • C5-OPS-06 Data Backup and Recovery - Concept
  • C5-OPS-07 Data Backup and Recovery - Monitoring
  • C5-OPS-08 Data Backup and Recovery - Regular Testing
  • C5-OPS-09 Data Backup and Recovery - Storage

HIPAA Security Rule · 4 controls

ISO 27001:2022 · 4 controls

  • 5.30 ICT readiness for business continuity
  • 5.33 Protection of records
  • 8.13 Information backup
  • 8.33 Test information

NIST SP 800-66 Rev 2 · 4 controls

PCI DSS 4.0 · 4 controls

  • 10.3.3 10.3.3 Audit logs promptly backed up to central secure storage
  • 12.3.1 12.3.1 Targeted risk analysis for flexible-frequency requirements
  • 9.4.1.1 9.4.1.1 Secure storage location for offline backups
  • 9.4.1.2 9.4.1.2 Annual review of offline backup location security

SOC 2 · 4 controls

  • SOC2-A1.2 A1.2 Environmental protection, backup and recovery infrastructure
  • SOC2-A1.3 A1.3 Testing recovery plan procedures
  • SOC2-CC6.8 CC6.8 Preventing and detecting unauthorised or malicious software
  • SOC2-PI1.5 PI1.5 Controls over stored inputs, work in process and outputs

ACSC Essential Eight · 3 controls

  • E8-BACKUP-ML1 Regular Backups (ML1)
  • E8-BACKUP-ML2 Regular Backups (ML2)
  • E8-BACKUP-ML3 Regular Backups (ML3)
  • CFTC-SS-10 Geographic Dispersal of Backup Infrastructure and Personnel
  • CFTC-SS-11 Testing and Review of Business Continuity and Disaster Recovery Capabilities
  • CFTC-SS-8 Business Continuity and Disaster Recovery Plan and Resources

ISO 27002:2022 · 3 controls

  • 5.30 ICT readiness for business continuity
  • 7.10 Storage media
  • 8.13 Information backup
  • ANSSI-HYG-37 Define and Apply a Backup Policy for Critical Components

APPI · 1 control

CMMC 2.0 · 1 control

DORA · 1 control

  • DORA-Art.12 Backup policies and procedures, restoration and recovery

ETSI EN 303 645 · 1 control

  • EN303645-5.11 Make it easy for users to delete user data

GDPR · 1 control

ISO 22301:2019 · 1 control

  • 8.3.5 Implementation of solutions

ISO 27701:2019 · 1 control

NIS2 Directive · 1 control

  • Art.21.2.c Business continuity, backup management, disaster recovery and crisis management
  • PR.IP-4 PR.IP-4: Backups of information are conducted, maintained, and tested periodically
  • PR.IP-4 PR.IP-4: Backups of information are conducted, maintained, and tested
  • 03.08.09 System Backup - Cryptographic Protection

NIST SP 800-218 · 1 control

  • PR.DS-11 PR.DS-11 Backups created, protected, maintained and tested for recovery

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in PR - Protect

You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done?

NIST Cybersecurity Framework 2.0 NIST-CSF-PR.DS-11 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 87 it maps to, and the evidence behind each claim, over MCP and REST.