NIST SP 800-53 Rev 5 MODERATE
CP Contingency Planning

NIST SP 800-53 Rev 5 MODERATE CP-10: System Recovery and Reconstitution

Provide for recovery and reconstitution of system to known state within RTO.

What else in your programme already covers this

This control maps to 46 controls across 21 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-PR.IR-03 Mechanisms are implemented to achieve resilience requirements in normal and adverse situations
  • NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process
  • NIST-CSF-RC.RP-03 The integrity of backups and other restoration assets is verified before using them for restoration
  • NIST-CSF-RC.RP-04 Critical mission functions and cybersecurity risk management are considered to establish post-incident operational norms
  • NIST-CSF-RC.RP-05 The integrity of restored assets is verified, systems and services are restored, and normal operating status is confirmed
  • NIST-CSF-RC.RP-06 The end of incident recovery is declared based on criteria, and incident-related documentation is completed

CIS Controls v8 · 4 controls

  • CIS-11.1 Establish and Maintain a Data Recovery Process
  • CIS-11.2 Perform Automated Backups
  • CIS-11.4 Establish and Maintain an Isolated Instance of Recovery Data
  • CIS-11.5 Test Data Recovery

ISO 27002:2022 · 4 controls

  • 5.29 Information security during disruption
  • 5.30 ICT readiness for business continuity
  • 8.13 Information backup
  • 8.32 Change management

SOC 2 · 4 controls

  • SOC2-A1.2 Environmental protections, data backups, and recovery infrastructure support availability
  • SOC2-A1.3 Recovery plan procedures support system recovery from failures
  • SOC2-CC7.5 Identifies the root cause of security incidents
  • SOC2-PI1.4 System outputs are complete, valid, accurate, timely, and distributed
  • CPS230-19 Tolerance Levels for Each Critical Operation
  • CPS230-20 Prevention, Adaptation and Return to Normal Operations
  • CPS230-P41 BCP Execution Capability and Tolerance Breach Reporting

ISO 27001:2022 · 3 controls

  • 5.29 Information security during disruption
  • 5.30 ICT readiness for business continuity
  • 8.13 Information backup
  • ASD37-34 Regular backups (Essential)
  • ASD37-36 System recovery capabilities (Very Good)

C5 (Germany) · 2 controls

  • C5-BCM-03 Planning business continuity
  • C5-OPS-08 Data Backup and Recovery - Regular Testing
  • CFTC-SS-25 Same Day Recovery Time Objective for Critical Entities
  • CFTC-SS-9 Next Business Day Recovery Time Objective

DORA · 2 controls

  • ANSSI-HYG-37 Define and Apply a Backup Policy for Critical Components

GDPR · 1 control

HIPAA Security Rule · 1 control

ISO 22301:2019 · 1 control

ISO 27701:2019 · 1 control

NIS2 Directive · 1 control

  • Art.21.2.c Business continuity, backup management, disaster recovery and crisis management

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in CP Contingency Planning

Query this from an agent

The graph holds this control, the 46 it maps to, and the evidence behind each claim, over MCP and REST.