NRC 10 CFR 73.54 - Nuclear Facility Cybersecurity
Regulatory Guide 5.71 Appendix C Security Controls

NRC 10 CFR 73.54 - Nuclear Facility Cybersecurity RG5.71-C.5: Recovery and Restoration

Licensees must have procedures to recover and restore critical digital assets following a cyber security event.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 266 controls across 109 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-DE.AE-08 Incidents are declared when adverse events meet the defined incident criteria
  • NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
  • NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process
  • NIST-CSF-RC.RP-06 The end of incident recovery is declared based on criteria, and incident-related documentation is completed
  • NIST-CSF-RS.MA-05 The criteria for initiating incident recovery are applied
  • PICERL-C2 System Backup
  • PICERL-P2 Risk Assessment
  • PICERL-P3 CSIRT Formation
  • PICERL-R1 System Restoration
  • PICERL-R2 Security Verification
  • SSAE18-A1.2 A1.2 - Environmental Protections and Recovery
  • SSAE18-A1.3 A1.3 - Recovery Plan Testing
  • SSAE18-CC7.4 CC7.4 - Incident Response
  • SSAE18-CC7.5 CC7.5 - Incident Recovery
  • SSAE18-PI1.1 PI1.1 - Processing Integrity Definition
  • DA-1 Enterprise Data Architecture
  • DIQ-1 Data Integration and Interoperability
  • DIQ-2 Data Quality Management
  • RMD-1 Reference Data Management

ISO 22320:2018 · 4 controls

  • ISO-22320-5.1 General process requirements
  • ISO-22320-5.2 Incident management process
  • ISO-22320-5.3 Incident management structure (command)
  • ISO-22320-5.4 Roles and responsibilities

ISO/IEC 27031:2011 · 4 controls

  • 27031-5.1 IRBC Policy
  • 27031-8.1 Exercising and Testing
  • 27031-8.2 Maintaining IRBC
  • 27031-9.3 Management Review

SOC 2 · 4 controls

  • SOC2-A1.2 A1.2 Environmental protection, backup and recovery infrastructure
  • SOC2-A1.3 A1.3 Testing recovery plan procedures
  • SOC2-CC4.2 CC4.2 Evaluating and communicating control deficiencies (COSO principle 17)
  • SOC2-CC7.4 CC7.4 Responding to security incidents

API 1164 · 3 controls

  • API1164-17 Wireless and Field Communications
  • API1164-18 Field Device Security
  • API1164-19 Safety Instrumented Systems Interface
  • ASD37-34 Regular backups (Essential)
  • ASD37-35 Business continuity and disaster recovery plans (Very Good)
  • ASD37-36 System recovery capabilities (Very Good)
  • IEC62304-5.2 Software Requirements Analysis
  • IEC62304-5.3 Software Architectural Design
  • IEC62304-7.2 Risk Control Measures

IEC 62443 · 3 controls

  • IEC62443-16 Incident response plan for operational disruptions
  • IEC62443-17 Recovery plan for critical systems
  • IEC62443-20 Exercises and drills for OT incidents
  • ISO-15189-5.1 Legal entity
  • ISO-15189-5.4 Structure and authority
  • ISO-15189-6.7 Service agreements
  • ISO-19650-1-4 Information management concepts
  • ISO-19650-1-7 Common Data Environment (CDE) concept
  • ISO-19650-3-5.3 Trigger events for information exchange

ISO/IEC 23894:2023 · 3 controls

  • ISO23894-1 Scope of AI Risk Management
  • ISO23894-3 AI-Specific Terminology
  • ISO23894-6.2 Scope, Context and Criteria

ISO/IEC 27004:2016 · 3 controls

  • 27004-3 Terms and definitions
  • 27004-A.2 Patching and Vulnerability Measures
  • 27004-B.1 Example measurement definitions

ISO/IEC 27011:2024 · 3 controls

  • 27011-1 Scope
  • 27011-3 Terms and definitions
  • 27011-8.6 Data protection and backup

ISO/IEC 27019:2024 · 3 controls

  • ISO27019-16 Incident response plan for operational disruptions
  • ISO27019-18 Reporting obligations to authorities
  • ISO27019-20 Exercises and drills for OT incidents
  • 27557-1 Scope
  • 27557-3 Terms and definitions
  • 27557-6.2 Scope, context, and criteria for privacy

ISO/IEC 29100:2024 · 3 controls

  • 29100-1 Scope
  • 29100-3 Terms and definitions
  • 29100-4.1 Actors and roles

NIST SP 1800-32 · 3 controls

South Korea ISMS-P · 3 controls

  • ISMSP-PI-06 Personal Information Destruction
  • ISMSP-SYS-04 Vulnerability Management
  • ISMSP-SYS-06 Business Continuity and Disaster Recovery
  • TRINIDAD-1 Scope, Definitions, Commission
  • TRINIDAD-2 Lawful Processing and Consent
  • TRINIDAD-3 Data Subject Rights
  • 58.1 Scope
  • 58.3 Definitions
  • 4.4.1 Resources, Roles, Responsibility, and Authority
  • 4.4.8 Business Continuity and Recovery
  • AL-DPA-1 Scope and Definitions
  • AL-DPA-3 Lawful Basis for Processing
  • AT-DSG-2 Section 2 - Scope and application
  • AT-DSG-8 Section 22 - Functions and powers of the DPA
  • MLE.1 Machine Learning Requirements Analysis
  • MLE.3 Machine Learning Training
  • FFIEC-05 Roles and responsibilities definition
  • FFIEC-12 Disaster recovery procedures

FedRAMP Rev 5 · 2 controls

  • FEDRAMP-CM-6 Configuration Settings
  • FEDRAMP-CP-9 System Backup
  • FDBR-702 Definitions (§501.702)
  • FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704)
  • 60601-1.3 Terminology and definitions
  • 60601-1.4.1 General requirements
  • ISO-20400-4.2 Principles of sustainable procurement
  • ISO-20400-7.2 Integrating sustainability into specifications

ISO 22316 · 2 controls

  • ISO22316-08 Recovery time and point objectives
  • ISO22316-12 Recovery strategy for critical activities
  • ISO-41001-4.1 Understanding the organization and its context
  • ISO-41001-4.3 Determining the scope of the FM management system

ISO 56002 · 2 controls

  • ISO-56002-4.3 Determining the scope of the innovation management system
  • ISO-56002-8.3.4 Develop solutions
  • ISO8000-DQM-02 Data Quality Dimensions
  • ISO8000-MDG-03 Continuous Improvement
  • ISO-17025-5.1 Legal entity
  • ISO-17025-5.4 Personnel for the management system
  • ISO-25012-5.2 Defining data quality measures
  • ISO-25012-5.3 Planning and performing data quality evaluations

ISO/IEC 27014:2020 · 2 controls

  • 27014-1 Scope
  • 27014-3 Terms and definitions

ISO/IEC 27043:2015 · 2 controls

  • ISO27043-04 Roles and responsibilities definition
  • ISO27043-23 Backup and recovery procedures

ISO/IEC 29147:2018 · 2 controls

  • 29147-3 Terms and definitions
  • 29147-9.2 Contact mechanisms and scope

ISO/IEC 30111:2019 · 2 controls

  • 30111-3 Terms and definitions
  • 30111-5.1 Organizational policy

ISO/SAE 21434 · 2 controls

  • ISO21434-04 Roles and responsibilities definition
  • ISO21434-23 Backup and recovery procedures

ISO/TS 22317:2021 · 2 controls

  • ISO22317-08 Recovery time and point objectives
  • ISO22317-12 Recovery strategy for critical activities

ISO/TS 22318:2021 · 2 controls

  • ISO22318-08 Recovery time and point objectives
  • ISO22318-12 Recovery strategy for critical activities
  • STANAG-1 STANAG 4774 Confidentiality Label Schema and XML Structure
  • STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding
  • NFPA1600-5.3 Resource Needs Assessment
  • NFPA1600-6.4 Continuity and Recovery

NIST SP 800-190 · 2 controls

NIST SP 800-53 Rev 5 · 2 controls

  • NDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • NDPA-5 Privacy Notice, Data Minimisation, and Purpose Limitation

OWASP SAMM · 2 controls

  • OWASPSAMM-1 Governance: Strategy, Policy, Compliance, Education, Champions
  • OWASPSAMM-5 Operations: Incident Management, Environment Management, Operational Management

PCI P2PE · 2 controls

  • PCI-P2PE-05 Roles and responsibilities definition
  • PCI-P2PE-12 Disaster recovery procedures

PCI PIN Security · 2 controls

  • PCI-PIN-05 Roles and responsibilities definition
  • PCI-PIN-12 Disaster recovery procedures

PCI SSF · 2 controls

  • PCI-SSF-05 Roles and responsibilities definition
  • PCI-SSF-12 Disaster recovery procedures
  • SHAREASSESS-1 Information Governance and Risk
  • SHAREASSESS-4 Vulnerability Management, Patching, Application Security

SLSA · 2 controls

  • SUPCHAIN-1 Build Integrity - Source, Build, Provenance
  • SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule
  • C1 Organizational Boundary
  • C3 Scope 1 and 2 Coverage
  • IM8-RES.2 Disaster Recovery
  • IM8-RES.4 Resilience Testing
  • TANZANIA-1 Scope, Registration, Lawful Basis
  • TANZANIA-4 Security and Cross-Border

UK Bribery Act 2010 · 2 controls

  • Section 6(5) Definition of Foreign Public Official
  • Section 8 Definition of Associated Person
  • UKGAMBLE-1 Scope and Applicability to Licensees
  • UKGAMBLE-4 Resilience and Incident Response
  • US-SEC-DA-SC-01 Howey Test Application
  • US-SEC-DA-SC-02 Registration Requirements
  • CFR211-A-3 Section 211.3 - Definitions
  • AZ-DPA-2 Article 2 - Basic Concepts
  • CPG-6.B Supply Chain Incident Reporting

COBIT 2019 · 1 control

  • COBIT-BAI02 Managed requirements definition
  • CTDPA-1 Definitions
  • FTC-Safeguards-Scope-Defs Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2)

FedRAMP High · 1 control

  • CA-9 Internal System Connections

FedRAMP Moderate · 1 control

  • CA-9 Internal System Connections
  • Sapin2-Pillar1-Code-of-Conduct Pillar 1 - Anti-Corruption Code of Conduct
  • ICP-1 Objectives, Powers and Responsibilities of the Supervisor
  • 62351-2 Glossary of terms
  • ISO-14064-1-5.1 Organizational boundaries
  • ISO-26262-3-5 Item definition
  • ISO28001-PI-01 Personnel Security Screening

ISO/IEC 23837:2023 · 1 control

  • 23837-1.1 Scope

ISO/IEC 27003:2017 · 1 control

  • ISO27003-4.3 Determining the scope of the information security management system

ISO/IEC 27007:2020 · 1 control

  • 27007-5.2 Audit Programme Objectives
  • 27050-1.4 Terms and definitions

ISO/IEC 27400:2022 · 1 control

  • 27400-3 Terms and definitions
  • 29115-3 Terms and definitions

ISO/IEC 29134:2023 · 1 control

  • 29134-3 Terms and definitions
  • BIPA-SEC5-1 Biometric Identifier Definition

PCI DSS 4.0 · 1 control

  • 2.2.2 2.2.2 Vendor default accounts managed
  • RIDTPPA-1 Scope, Applicability, Definitions
  • SCA-S2 Interpretation and Definitions
  • SWE-2 Relationship to GDPR
  • TSAPIPE-2 OT/IT Network Segmentation and Access Control
  • UKGDPRREG-1 Subject Matter, Scope, Principles (Articles 1-11)
  • OB-OPS.2 Performance Standards
  • UK-TSA-NET-01 Security Architecture
  • 15 U.S.C. § 78dd-2(h) Definition of Domestic Concern

WCAG 2.2 · 1 control

  • WCAGREC-3 Principle 3: Understandable
  • SO2.2 Digital health architecture blueprint

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Regulatory Guide 5.71 Appendix C Security Controls

Query this from an agent

The graph holds this control, the 266 it maps to, and the evidence behind each claim, over MCP and REST.