Frameworks / NIST SP 800-66 Rev 2 / 164.308(a)(7)(ii)(A) NIST SP 800-66 Rev 2
Administrative
NIST SP 800-66 Rev 2 164.308(a)(7)(ii)(A): Data Backup Plan (Required) Establish procedures to create and maintain retrievable exact copies of ePHI. NIST recommends offline or immutable backups, encryption, and regular restoration testing.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 45 controls across 22 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
CIS-11.1 Establish and Maintain a Data Recovery Process CIS-11.2 Perform Automated Backups CIS-11.3 Protect Recovery Data CIS-11.4 Establish and Maintain an Isolated Instance of Recovery Data CIS-11.5 Test Data Recovery SOC2-A1.2 A1.2 Environmental protection, backup and recovery infrastructure SOC2-A1.3 A1.3 Testing recovery plan procedures SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11) SOC2-CC6.5 CC6.5 Protecting data on assets until disposal SOC2-PI1.1 PI1.1 Quality information about processing objectives, data definitions and specifications E8-BACKUP-ML1 Regular Backups (ML1) E8-BACKUP-ML2 Regular Backups (ML2) E8-BACKUP-ML3 Regular Backups (ML3) C5-OPS-06 Data Backup and Recovery - Concept C5-OPS-08 Data Backup and Recovery - Regular Testing C5-OPS-09 Data Backup and Recovery - Storage CFTC-SS-11 Testing and Review of Business Continuity and Disaster Recovery Capabilities CFTC-SS-37 Protection of Swap Data Repository Data CFTC-SS-8 Business Continuity and Disaster Recovery Plan and Resources CP-9 System Backup CP-9(1) Testing for Reliability and Integrity CP-9(8) System Backup | Cryptographic Protection (CP-9(8)) CP-9 System Backup CP-9(1) Testing for Reliability and Integrity CP-9(8) System Backup | Cryptographic Protection (CP-9(8)) BR-1 Ensure regular automated backups BR-2 Protect backup and recovery data 8.3.4 Resource requirements 8.3.5 Implementation of solutions 8.13 Information backup 8.27 Secure system architecture and engineering principles NIST-CSF-PR.DS-11 Backups of data are created, protected, maintained, and tested NIST-CSF-RC.RP-03 The integrity of backups and other restoration assets is verified before using them for restoration 12.3.1 12.3.1 Targeted risk analysis for flexible-frequency requirements 9.4.1.1 9.4.1.1 Secure storage location for offline backups ANSSI-HYG-37 Define and Apply a Backup Policy for Critical Components CPS230-26 Critical Operations Register, Continuity Plan and Activation 03.08.09 System Backup - Cryptographic Protection Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in Administrative Query this from an agent The graph holds this control, the 45 it maps to, and the evidence behind each claim, over MCP and REST.