NIST SP 800-53 Rev 5
CP - Contingency Planning

NIST SP 800-53 Rev 5 NIST800-CP-9: CP-9 System Backup

a. Conduct backups of user-level information contained in [Assignment: organization-defined system components] [Assignment: organization-defined frequency consistent with recovery time and recovery point objectives]; b. Conduct backups of system-level information contained in the system [Assignment: organization-defined frequency consistent with recovery time and recovery point objectives]; c. Conduct backups of system documentation, including security- and privacy-related documentation [Assignment: organization-defined frequency consistent with recovery time and recovery point objectives]; and d. Protect the confidentiality, integrity, and availability of backup information.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 150 controls across 76 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-PR.DS-11 Backups of data are created, protected, maintained, and tested
  • NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process
  • NIST-CSF-RC.RP-03 The integrity of backups and other restoration assets is verified before using them for restoration
  • NIST-CSF-RC.RP-06 The end of incident recovery is declared based on criteria, and incident-related documentation is completed
  • NIST-CSF-RS.MA-05 The criteria for initiating incident recovery are applied

C5 (Germany) · 4 controls

  • C5-OPS-06 Data Backup and Recovery - Concept
  • C5-OPS-07 Data Backup and Recovery - Monitoring
  • C5-OPS-08 Data Backup and Recovery - Regular Testing
  • C5-OPS-09 Data Backup and Recovery - Storage

CIS Controls v8 · 4 controls

ISO 27701:2019 · 4 controls

  • 6.14 Information security aspects of business continuity management
  • 6.14.1 Information security continuity
  • 6.9.3 Backup
  • 7.4.7 Retention

ACSC Essential Eight · 3 controls

  • E8-BACKUP-ML1 Regular Backups (ML1)
  • E8-BACKUP-ML2 Regular Backups (ML2)
  • E8-BACKUP-ML3 Regular Backups (ML3)

API 1164 · 3 controls

  • API1164-17 Wireless and Field Communications
  • API1164-18 Field Device Security
  • API1164-19 Safety Instrumented Systems Interface
  • ASD37-34 Regular backups (Essential)
  • ASD37-35 Business continuity and disaster recovery plans (Very Good)
  • ASD37-36 System recovery capabilities (Very Good)

FedRAMP High · 3 controls

  • CP-9 System Backup
  • CP-9(1) Testing for Reliability and Integrity
  • CP-9(8) System Backup | Cryptographic Protection (CP-9(8))

FedRAMP Moderate · 3 controls

  • CP-9 System Backup
  • CP-9(1) Testing for Reliability and Integrity
  • CP-9(8) System Backup | Cryptographic Protection (CP-9(8))

HIPAA Security Rule · 3 controls

IEC 62443 · 3 controls

  • IEC62443-16 Incident response plan for operational disruptions
  • IEC62443-17 Recovery plan for critical systems
  • IEC62443-20 Exercises and drills for OT incidents

ISO 27001:2022 · 3 controls

  • 5.30 ICT readiness for business continuity
  • 8.13 Information backup
  • 8.6 Capacity management

ISO/IEC 27019:2024 · 3 controls

  • ISO27019-16 Incident response plan for operational disruptions
  • ISO27019-18 Reporting obligations to authorities
  • ISO27019-20 Exercises and drills for OT incidents

ISO/IEC 27031:2011 · 3 controls

  • 27031-8.1 Exercising and Testing
  • 27031-8.2 Maintaining IRBC
  • 27031-9.3 Management Review

NIST SP 1800-32 · 3 controls

NIST SP 800-66 Rev 2 · 3 controls

  • PICERL-C2 System Backup
  • PICERL-R1 System Restoration
  • PICERL-R2 Security Verification

SOC 2 · 3 controls

  • SOC2-A1.1 A1.1 Managing processing capacity
  • SOC2-A1.2 A1.2 Environmental protection, backup and recovery infrastructure
  • SOC2-A1.3 A1.3 Testing recovery plan procedures
  • SSAE18-A1.2 A1.2 - Environmental Protections and Recovery
  • SSAE18-A1.3 A1.3 - Recovery Plan Testing
  • SSAE18-CC7.5 CC7.5 - Incident Recovery

ISO 22301:2019 · 2 controls

ISO 22316 · 2 controls

  • ISO22316-08 Recovery time and point objectives
  • ISO22316-12 Recovery strategy for critical activities

ISO 27002:2022 · 2 controls

  • 5.30 ICT readiness for business continuity
  • 8.13 Information backup

ISO/TS 22317:2021 · 2 controls

  • ISO22317-08 Recovery time and point objectives
  • ISO22317-12 Recovery strategy for critical activities

ISO/TS 22318:2021 · 2 controls

  • ISO22318-08 Recovery time and point objectives
  • ISO22318-12 Recovery strategy for critical activities
  • NFPA1600-5.3 Resource Needs Assessment
  • NFPA1600-6.4 Continuity and Recovery

PCI DSS 4.0 · 2 controls

  • 10.3.3 10.3.3 Audit logs promptly backed up to central secure storage
  • 12.3.1 12.3.1 Targeted risk analysis for flexible-frequency requirements
  • IM8-RES.2 Disaster Recovery
  • IM8-RES.4 Resilience Testing

South Korea ISMS-P · 2 controls

  • ISMSP-PI-06 Personal Information Destruction
  • ISMSP-SYS-06 Business Continuity and Disaster Recovery
  • ANSSI-HYG-37 Define and Apply a Backup Policy for Critical Components
  • CPS230-19 Tolerance Levels for Each Critical Operation
  • 4.4.8 Business Continuity and Recovery
  • CFTC-SS-8 Business Continuity and Disaster Recovery Plan and Resources

CMMC 2.0 · 1 control

  • DIQ-1 Data Integration and Interoperability

DORA · 1 control

  • DORA-Art.12 Backup policies and procedures, restoration and recovery
  • FFIEC-12 Disaster recovery procedures

FedRAMP Rev 5 · 1 control

  • FEDRAMP-CP-9 System Backup

GDPR · 1 control

ISO 22320:2018 · 1 control

  • ISO-22320-5.2 Incident management process

ISO/IEC 27011:2024 · 1 control

  • 27011-8.6 Data protection and backup

ISO/IEC 27043:2015 · 1 control

  • ISO27043-23 Backup and recovery procedures

ISO/SAE 21434 · 1 control

  • ISO21434-23 Backup and recovery procedures

NIS2 Directive · 1 control

  • Art.21.2.c Business continuity, backup management, disaster recovery and crisis management
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)
  • 03.08.09 System Backup - Cryptographic Protection

NIST SP 800-190 · 1 control

  • CP-9 CP-9 System Backup
  • CP-9 CP-9 System Backup
  • CP-9 CP-9 System Backup
  • NISTSP82-7 OT Incident Response, Forensics, Recovery, and Continuity

NIST SP 800-88 · 1 control

  • NISTSP88-5 Media Inventory, Tracking, Chain of Custody, and Sanitization Records

NIST SP 800-92 · 1 control

  • NISTSP92-6 Log Retention: Policy, Tiered Storage, Backup, Secure Disposal, Legal Hold

OSFI B-13 · 1 control

  • OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery

OWASP SAMM · 1 control

  • OWASPSAMM-5 Operations: Incident Management, Environment Management, Operational Management
  • OMANCS-7 Business Continuity, Disaster Recovery, and Resilience
  • OPENBANK-8 Incident Detection, Response, Customer Notification, Post-Incident Review, BCM

OpenSSF Scorecard · 1 control

  • OSSFSC-8 Project Maintenance, Sustainability, Integration with Supply Chain Security

PCI P2PE · 1 control

  • PCI-P2PE-12 Disaster recovery procedures

PCI PIN Security · 1 control

  • PCI-PIN-12 Disaster recovery procedures

PCI SSF · 1 control

  • PCI-SSF-12 Disaster recovery procedures

PSD2 SCA · 1 control

  • PSDTWO-2 SCA Exemptions and Risk-Based Authentication

PTES · 1 control

  • PTESPHASE-3 Threat Modeling
  • SHAREASSESS-4 Vulnerability Management, Patching, Application Security

SLSA · 1 control

  • SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule
  • TSAPIPE-2 OT/IT Network Segmentation and Access Control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in CP - Contingency Planning

You are reading one control. How much of NIST SP 800-53 Rev 5 have you already done?

NIST SP 800-53 Rev 5 NIST800-CP-9 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST SP 800-53 Rev 5 your existing evidence covers. Hold ISO 27001:2022 and 163 of 1014 NIST SP 800-53 Rev 5 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 342 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 150 it maps to, and the evidence behind each claim, over MCP and REST.