SANS Incident Handler's Handbook and PICERL Methodology
Phase 5 - Recovery

SANS Incident Handler's Handbook and PICERL Methodology PICERL-R1: System Restoration

Restore systems to normal operation ensuring they are free from security loopholes

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 85 controls across 42 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

API 1164 · 3 controls

  • ASD37-34 Regular backups (Essential)
  • ASD37-35 Business continuity and disaster recovery plans (Very Good)
  • ASD37-36 System recovery capabilities (Very Good)

IEC 62443 · 3 controls

ISO 27019 · 3 controls

ISO/IEC 27031:2011 · 3 controls

  • NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process
  • NIST-CSF-RC.RP-06 The end of incident recovery is declared based on criteria, and incident-related documentation is completed
  • NIST-CSF-RS.MA-05 The criteria for initiating incident recovery are applied

NIST SP 1800-32 · 3 controls

ISO 22316 · 2 controls

ISO 22317 · 2 controls

ISO 22318 · 2 controls

NIST SP 800-53 Rev 5 · 2 controls

SOC 2 · 2 controls

  • SOC2-A1.2 Environmental protections, data backups, and recovery infrastructure support availability
  • SOC2-A1.3 Recovery plan procedures support system recovery from failures

South Korea ISMS-P · 2 controls

  • 4.4.8 Business Continuity and Recovery
  • DIQ-1 Data Integration and Interoperability

ISO 22320:2018 · 1 control

ISO 27017 · 1 control

ISO 27018 · 1 control

ISO 27043 · 1 control

ISO/IEC 27011:2024 · 1 control

ISO/SAE 21434 · 1 control

NIST SP 800-190 · 1 control

OWASP SAMM · 1 control

  • OWASPSAMM-5 Operations: Incident Management, Environment Management, Operational Management

PCI P2PE · 1 control

PCI PIN Security · 1 control

PCI SSF · 1 control

PSD2 SCA · 1 control

  • PSDTWO-2 SCA Exemptions and Risk-Based Authentication

PTES · 1 control

  • SHAREASSESS-4 Vulnerability Management, Patching, Application Security

SLSA · 1 control

  • SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule
  • TSAPIPE-2 OT/IT Network Segmentation and Access Control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Phase 5 - Recovery

Query this from an agent

The graph holds this control, the 85 it maps to, and the evidence behind each claim, over MCP and REST.