SOC 2
A - Availability

SOC 2 SOC2-A1.2: A1.2 Environmental protection, backup and recovery infrastructure

Protection against environmental events, the supporting software, backup processes and recovery infrastructure are authorised, designed or acquired, implemented, operated, approved, maintained and monitored to meet objectives. Points of focus: environmental threats such as weather, failed environmental controls, electrical discharge, fire and water are identified in risk assessment; detection, protection mechanisms and alerts address them; response procedures, including automatic systems such as UPS and generators, are in place and evaluated; detected events are reviewed and acted on; data needing backup is determined; backups run with failure monitoring and correction; backups are stored far enough away that one event is unlikely to affect both copies; and alternate processing infrastructure can take over. The 2022 revision adds identifying threats to data recoverability, such as ransomware, and the measures that mitigate them, and notes that alternate processing can rely on geographically separate sites, redundant components and failover.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 301 controls across 75 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

FedRAMP High · 24 controls

  • CP-10 System Recovery and Reconstitution
  • CP-2 Contingency Plan
  • CP-2(8) Contingency Plan | Identify Critical Assets (CP-2(8))
  • CP-6 Alternate Storage Site
  • CP-6(3) Alternate Storage Site | Accessibility (CP-6(3))
  • CP-7 Alternate Processing Site
  • CP-7(1) Alternate Processing Site | Separation from Primary Site (CP-7(1))
  • CP-8 Telecommunications Services
  • CP-8(1) Telecommunications Services | Priority of Service Provisions (CP-8(1))
  • CP-8(2) Telecommunications Services | Single Points of Failure (CP-8(2))
  • CP-9 System Backup
  • CP-9(1) Testing for Reliability and Integrity
  • IR-3 Incident Response Testing
  • MA-2 Controlled Maintenance
  • PE-10 Emergency Shutoff (PE-10)
  • PE-11 Emergency Power (PE-11)
  • PE-12 Emergency Lighting
  • PE-13 Fire Protection
  • PE-13(2) Fire Protection | Suppression Systems: Automatic Activation and Notification (PE-13(2))
  • PE-14 Environmental Controls
  • PE-15 Water Damage Protection (PE-15)
  • PE-17 Alternate Work Site
  • PE-9 Power Equipment and Cabling (PE-9)
  • SC-22 Architecture and Provisioning for Name/Address Resolution Service

FedRAMP Moderate · 24 controls

  • CP-10 System Recovery and Reconstitution
  • CP-2 Contingency Plan
  • CP-2(8) Contingency Plan | Identify Critical Assets (CP-2(8))
  • CP-6 Alternate Storage Site
  • CP-6(3) Alternate Storage Site | Accessibility (CP-6(3))
  • CP-7 Alternate Processing Site
  • CP-7(1) Alternate Processing Site | Separation from Primary Site (CP-7(1))
  • CP-8 Telecommunications Services
  • CP-8(1) Telecommunications Services | Priority of Service Provisions (CP-8(1))
  • CP-8(2) Telecommunications Services | Single Points of Failure (CP-8(2))
  • CP-9 System Backup
  • CP-9(1) Testing for Reliability and Integrity
  • IR-3 Incident Response Testing
  • MA-2 Controlled Maintenance
  • PE-10 Emergency Shutoff (PE-10)
  • PE-11 Emergency Power (PE-11)
  • PE-12 Emergency Lighting
  • PE-13 Fire Protection
  • PE-13(2) Fire Protection | Suppression Systems: Automatic Activation and Notification (PE-13(2))
  • PE-14 Environmental Controls
  • PE-15 Water Damage Protection (PE-15)
  • PE-17 Alternate Work Site
  • PE-9 Power Equipment and Cabling (PE-9)
  • SC-22 Architecture and Provisioning for Name/Address Resolution Service

NIST SP 800-53 Rev 5 · 22 controls

  • NIST-CSF-DE.CM-02 The physical environment is monitored to find potentially adverse events
  • NIST-CSF-PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected
  • NIST-CSF-PR.DS-10 The confidentiality, integrity, and availability of data-in-use are protected
  • NIST-CSF-PR.DS-11 Backups of data are created, protected, maintained, and tested
  • NIST-CSF-PR.IR-02 The organization's technology assets are protected from environmental threats
  • NIST-CSF-PR.IR-03 Mechanisms are implemented to achieve resilience requirements in normal and adverse situations
  • NIST-CSF-PR.IR-04 Adequate resource capacity to ensure availability is maintained
  • NIST-CSF-PR.PS-03 Hardware is maintained, replaced, and removed commensurate with risk
  • NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process
  • NIST-CSF-RC.RP-03 The integrity of backups and other restoration assets is verified before using them for restoration
  • NIST-CSF-RC.RP-04 Critical mission functions and cybersecurity risk management are considered to establish post-incident operational norms
  • NIST-CSF-RC.RP-05 The integrity of restored assets is verified, systems and services are restored, and normal operating status is confirmed
  • NIST-CSF-RC.RP-06 The end of incident recovery is declared based on criteria, and incident-related documentation is completed
  • NIST-CSF-RS.MA-05 The criteria for initiating incident recovery are applied

ISO 27001:2022 · 9 controls

  • 5.29 Information security during disruption
  • 5.30 ICT readiness for business continuity
  • 5.33 Protection of records
  • 7.11 Supporting utilities
  • 7.13 Equipment maintenance
  • 7.5 Protecting against physical and environmental threats
  • 7.8 Equipment siting and protection
  • 8.13 Information backup
  • 8.14 Redundancy of information processing facilities

ISO 27002:2022 · 9 controls

  • 5.29 Information security during disruption
  • 5.30 ICT readiness for business continuity
  • 5.33 Protection of records
  • 7.11 Supporting utilities
  • 7.13 Equipment maintenance
  • 7.5 Protecting against physical and environmental threats
  • 7.8 Equipment siting and protection
  • 8.13 Information backup
  • 8.14 Redundancy of information processing facilities

C5 (Germany) · 8 controls

  • C5-BCM-01 Top management responsibility
  • C5-OPS-06 Data Backup and Recovery - Concept
  • C5-OPS-07 Data Backup and Recovery - Monitoring
  • C5-PS-01 Physical Security and Environmental Control Requirements
  • C5-PS-02 Redundancy model
  • C5-PS-05 Protection from fire and smoke
  • C5-PS-06 Protection against interruptions caused by power failures and other such risks
  • C5-PS-07 Surveillance of operational and environmental parameters

HIPAA Security Rule · 6 controls

ISO 27701:2019 · 6 controls

  • 5.5 Support
  • 6.14 Information security aspects of business continuity management
  • 6.14.1 Information security continuity
  • 6.14.2 Redundancies
  • 6.8.2 Equipment
  • 6.9.3 Backup

NIST SP 800-66 Rev 2 · 6 controls

CIS Controls v8 · 5 controls

  • CIS-11.1 Establish and Maintain a Data Recovery Process
  • CIS-11.2 Perform Automated Backups
  • CIS-11.3 Protect Recovery Data
  • CIS-11.4 Establish and Maintain an Isolated Instance of Recovery Data
  • CIS-11.5 Test Data Recovery

CMMC 2.0 · 5 controls

  • ASD37-20 Multi-factor authentication (Essential)
  • ASD37-34 Regular backups (Essential)
  • ASD37-35 Business continuity and disaster recovery plans (Very Good)
  • ASD37-36 System recovery capabilities (Very Good)
  • 4.3.2 Legal and Other Requirements
  • 4.4.1 Resources, Roles, Responsibility, and Authority
  • 4.4.2 Competence, Training, and Awareness
  • 4.4.8 Business Continuity and Recovery
  • ASBv3-BR-3 Monitor backups
  • ASBv3-GS-8 Define and implement backup and recovery strategy
  • BR-1 Ensure regular automated backups
  • BR-2 Protect backup and recovery data

ISO 22301:2019 · 4 controls

ISO/IEC 27031:2011 · 4 controls

  • 27031-8.1 Exercising and Testing
  • 27031-8.2 Maintaining IRBC
  • 27031-9.3 Management Review
  • 27031-B High availability embedded systems

PCI DSS 4.0 · 4 controls

  • 10.3.3 10.3.3 Audit logs promptly backed up to central secure storage
  • 12.3.1 12.3.1 Targeted risk analysis for flexible-frequency requirements
  • 9.4.1.1 9.4.1.1 Secure storage location for offline backups
  • 9.4.1.2 9.4.1.2 Annual review of offline backup location security

PCI PIN Security · 4 controls

  • PCI-PIN-12 Disaster recovery procedures
  • PCI-PIN-13 Third-party dependency management
  • PCI-PIN-14 Critical service identification
  • PCI-PIN-15 Communication and escalation procedures
  • SSAE18-A1.1 A1.1 - Availability Commitments and Requirements
  • SSAE18-A1.2 A1.2 - Environmental Protections and Recovery
  • SSAE18-A1.3 A1.3 - Recovery Plan Testing
  • SSAE18-CC7.5 CC7.5 - Incident Recovery
  • IM8-DAT.2 Data Protection
  • IM8-DSS.2 Service Reliability Standards
  • IM8-RES.2 Disaster Recovery
  • IM8-RES.4 Resilience Testing

ACSC Essential Eight · 3 controls

  • E8-BACKUP-ML1 Regular Backups (ML1)
  • E8-BACKUP-ML2 Regular Backups (ML2)
  • E8-BACKUP-ML3 Regular Backups (ML3)

API 1164 · 3 controls

  • API1164-17 Wireless and Field Communications
  • API1164-18 Field Device Security
  • API1164-19 Safety Instrumented Systems Interface
  • CFTC-SS-22 Business Continuity and Disaster Recovery Planning Category
  • CFTC-SS-6 Physical Security and Environmental Controls Category
  • CFTC-SS-8 Business Continuity and Disaster Recovery Plan and Resources
  • FFIEC-11 Business continuity planning and testing
  • FFIEC-12 Disaster recovery procedures
  • FFIEC-14 Critical service identification

IEC 62443 · 3 controls

  • IEC62443-16 Incident response plan for operational disruptions
  • IEC62443-17 Recovery plan for critical systems
  • IEC62443-20 Exercises and drills for OT incidents

ISO/IEC 27019:2024 · 3 controls

  • ISO27019-16 Incident response plan for operational disruptions
  • ISO27019-18 Reporting obligations to authorities
  • ISO27019-20 Exercises and drills for OT incidents

NIST SP 1800-32 · 3 controls

PCI P2PE · 3 controls

  • PCI-P2PE-11 Business continuity planning and testing
  • PCI-P2PE-12 Disaster recovery procedures
  • PCI-P2PE-14 Critical service identification

PCI SSF · 3 controls

  • PCI-SSF-12 Disaster recovery procedures
  • PCI-SSF-14 Critical service identification
  • PCI-SSF-15 Communication and escalation procedures
  • PICERL-C2 System Backup
  • PICERL-R1 System Restoration
  • PICERL-R2 Security Verification

APRA CPS 234 · 2 controls

  • CPS234-14 Definition of Information Security Roles and Responsibilities
  • CPS234-15 Information Security Capability
  • DIQ-1 Data Integration and Interoperability
  • RMD-1 Reference Data Management

DORA · 2 controls

  • DORA-Art.12 Backup policies and procedures, restoration and recovery
  • DORA-Art.7 ICT systems, protocols and tools
  • 62351-12 Resilience and security recommendations for DER
  • 62351-13 Cyber-physical generation and storage resilience

ISO 22316 · 2 controls

  • ISO22316-08 Recovery time and point objectives
  • ISO22316-12 Recovery strategy for critical activities

ISO/TS 22317:2021 · 2 controls

  • ISO22317-08 Recovery time and point objectives
  • ISO22317-12 Recovery strategy for critical activities

ISO/TS 22318:2021 · 2 controls

  • ISO22318-08 Recovery time and point objectives
  • ISO22318-12 Recovery strategy for critical activities
  • NFPA1600-5.3 Resource Needs Assessment
  • NFPA1600-6.4 Continuity and Recovery
  • SOC-CY-A1 Availability Commitments
  • SOC-CY-A2 Disaster Recovery
  • SOCI-S30BC Notification of critical cyber security incidents (12 hours)
  • SOCI-S30BD Notification of other cyber security incidents (72 hours)

South Korea ISMS-P · 2 controls

  • ISMSP-PI-06 Personal Information Destruction
  • ISMSP-SYS-06 Business Continuity and Disaster Recovery
  • OB-API.4 MI Reporting Specification
  • OB-OPS.1 API Availability Requirements
  • SEMD-CS-3 Cyber Resilience
  • SEMD-ER-1 Emergency Exercise and Testing

AICPA SOC 3 · 1 control

  • SOC3-AVAILABILITY Availability Criteria
  • ANSSI-HYG-37 Define and Apply a Backup Policy for Critical Components
  • CPS230-P41 BCP Execution Capability and Tolerance Breach Reporting
  • BS65000-RM-03 Leadership and Culture

COBIT 2019 · 1 control

  • COBIT-BAI04 Managed availability and capacity
  • CAT-D5-4 Resilience planning and testing

FedRAMP Rev 5 · 1 control

  • FEDRAMP-CP-9 System Backup

GDPR · 1 control

ISO 22320:2018 · 1 control

  • ISO-22320-5.2 Incident management process
  • ISO20000-03 Capacity and availability management
  • ISO-25012-4.13 Availability

ISO/IEC 27007:2020 · 1 control

  • 27007-5.4 Establishing the Programme Resources

ISO/IEC 27011:2024 · 1 control

  • 27011-8.6 Data protection and backup

ISO/IEC 27043:2015 · 1 control

  • ISO27043-23 Backup and recovery procedures

ISO/IEC 42001:2023 · 1 control

  • A.4.5 System and computing resources

ISO/SAE 21434 · 1 control

  • ISO21434-23 Backup and recovery procedures

ITIL 4 · 1 control

  • ITIL4-03 Capacity and availability management

NIS2 Directive · 1 control

  • Art.21.2.c Business continuity, backup management, disaster recovery and crisis management
  • 03.08.09 System Backup - Cryptographic Protection

NIST SP 800-190 · 1 control

SASB Standards · 1 control

  • SASB-BMI-2 Business Model Resilience
  • UKAI-3 Bias Detection, Fairness, Validation
  • UKOPRES-5 Third-Party Risk, Concentration Risk
  • CERT-1 RRA Certification to EPA

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in A - Availability

You are reading one control. How much of SOC 2 have you already done?

SOC 2 SOC2-A1.2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 301 it maps to, and the evidence behind each claim, over MCP and REST.