Frameworks / NIST SP 800-66 Rev 2 / 164.308(a)(7)(ii)(B) NIST SP 800-66 Rev 2
Administrative
NIST SP 800-66 Rev 2 164.308(a)(7)(ii)(B): Disaster Recovery Plan (Required) Establish procedures to restore lost data and resume operations. NIST recommends documented recovery procedures, alternate site arrangements, and aligned dependencies.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 57 controls across 20 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
CFTC-SS-10 Geographic Dispersal of Backup Infrastructure and Personnel CFTC-SS-22 Business Continuity and Disaster Recovery Planning Category CFTC-SS-26 Own Resources or Contractual Arrangements to Meet the Recovery Objective CFTC-SS-29 Recovery Plan Accounts for Essential Service Providers CFTC-SS-8 Business Continuity and Disaster Recovery Plan and Resources CFTC-SS-9 Next Business Day Recovery Time Objective 7.5.1 General 8.2 Business impact analysis and risk assessment 8.3.2 Identification of strategies and solutions 8.4.4 Business continuity plans 8.4.5 Recovery NIST-CSF-ID.IM-04 Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved NIST-CSF-PR.DS-11 Backups of data are created, protected, maintained, and tested NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process NIST-CSF-RC.RP-03 The integrity of backups and other restoration assets is verified before using them for restoration NIST-CSF-RC.RP-04 Critical mission functions and cybersecurity risk management are considered to establish post-incident operational norms CIS-11.1 Establish and Maintain a Data Recovery Process CIS-11.2 Perform Automated Backups CIS-11.4 Establish and Maintain an Isolated Instance of Recovery Data CIS-11.5 Test Data Recovery 5.29 Information security during disruption 5.30 ICT readiness for business continuity 7.5 Protecting against physical and environmental threats 8.13 Information backup CP-10 System Recovery and Reconstitution CP-6 Alternate Storage Site CP-7 Alternate Processing Site CP-10 System Recovery and Reconstitution CP-6 Alternate Storage Site CP-7 Alternate Processing Site 5.29 Information security during disruption 5.30 ICT readiness for business continuity 8.13 Information backup SOC2-A1.2 A1.2 Environmental protection, backup and recovery infrastructure SOC2-A1.3 A1.3 Testing recovery plan procedures SOC2-CC7.5 CC7.5 Recovering from security incidents CPS230-20 Prevention, Adaptation and Return to Normal Operations CPS230-26 Critical Operations Register, Continuity Plan and Activation ASD37-35 Business continuity and disaster recovery plans (Very Good) ASD37-36 System recovery capabilities (Very Good) E8-BACKUP-ML1 Regular Backups (ML1) ANSSI-HYG-37 Define and Apply a Backup Policy for Critical Components 6.14.1 Information security continuity 10.7.3 10.7.3 Respond promptly to critical security control failures Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in Administrative Query this from an agent The graph holds this control, the 57 it maps to, and the evidence behind each claim, over MCP and REST.