Frameworks / SOC 2 / SOC2-A1.2 SOC 2 SOC2-A1.2: A1.2 Environmental protection, backup and recovery infrastructure Protection against environmental events, the supporting software, backup processes and recovery infrastructure are authorised, designed or acquired, implemented, operated, approved, maintained and monitored to meet objectives. Points of focus: environmental threats such as weather, failed environmental controls, electrical discharge, fire and water are identified in risk assessment; detection, protection mechanisms and alerts address them; response procedures, including automatic systems such as UPS and generators, are in place and evaluated; detected events are reviewed and acted on; data needing backup is determined; backups run with failure monitoring and correction; backups are stored far enough away that one event is unlikely to affect both copies; and alternate processing infrastructure can take over. The 2022 revision adds identifying threats to data recoverability, such as ransomware, and the measures that mitigate them, and notes that alternate processing can rely on geographically separate sites, redundant components and failover.
Maintained by Gerard Blokdyk · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 301 controls across 75 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
CP-10 System Recovery and Reconstitution CP-2 Contingency Plan CP-2(8) Contingency Plan | Identify Critical Assets (CP-2(8)) CP-6 Alternate Storage Site CP-6(3) Alternate Storage Site | Accessibility (CP-6(3)) CP-7 Alternate Processing Site CP-7(1) Alternate Processing Site | Separation from Primary Site (CP-7(1)) CP-8 Telecommunications Services CP-8(1) Telecommunications Services | Priority of Service Provisions (CP-8(1)) CP-8(2) Telecommunications Services | Single Points of Failure (CP-8(2)) CP-9 System Backup CP-9(1) Testing for Reliability and Integrity IR-3 Incident Response Testing MA-2 Controlled Maintenance PE-10 Emergency Shutoff (PE-10) PE-11 Emergency Power (PE-11) PE-12 Emergency Lighting PE-13 Fire Protection PE-13(2) Fire Protection | Suppression Systems: Automatic Activation and Notification (PE-13(2)) PE-14 Environmental Controls PE-15 Water Damage Protection (PE-15) PE-17 Alternate Work Site PE-9 Power Equipment and Cabling (PE-9) SC-22 Architecture and Provisioning for Name/Address Resolution Service CP-10 System Recovery and Reconstitution CP-2 Contingency Plan CP-2(8) Contingency Plan | Identify Critical Assets (CP-2(8)) CP-6 Alternate Storage Site CP-6(3) Alternate Storage Site | Accessibility (CP-6(3)) CP-7 Alternate Processing Site CP-7(1) Alternate Processing Site | Separation from Primary Site (CP-7(1)) CP-8 Telecommunications Services CP-8(1) Telecommunications Services | Priority of Service Provisions (CP-8(1)) CP-8(2) Telecommunications Services | Single Points of Failure (CP-8(2)) CP-9 System Backup CP-9(1) Testing for Reliability and Integrity IR-3 Incident Response Testing MA-2 Controlled Maintenance PE-10 Emergency Shutoff (PE-10) PE-11 Emergency Power (PE-11) PE-12 Emergency Lighting PE-13 Fire Protection PE-13(2) Fire Protection | Suppression Systems: Automatic Activation and Notification (PE-13(2)) PE-14 Environmental Controls PE-15 Water Damage Protection (PE-15) PE-17 Alternate Work Site PE-9 Power Equipment and Cabling (PE-9) SC-22 Architecture and Provisioning for Name/Address Resolution Service NIST-CSF-DE.CM-02 The physical environment is monitored to find potentially adverse events NIST-CSF-PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected NIST-CSF-PR.DS-10 The confidentiality, integrity, and availability of data-in-use are protected NIST-CSF-PR.DS-11 Backups of data are created, protected, maintained, and tested NIST-CSF-PR.IR-02 The organization's technology assets are protected from environmental threats NIST-CSF-PR.IR-03 Mechanisms are implemented to achieve resilience requirements in normal and adverse situations NIST-CSF-PR.IR-04 Adequate resource capacity to ensure availability is maintained NIST-CSF-PR.PS-03 Hardware is maintained, replaced, and removed commensurate with risk NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process NIST-CSF-RC.RP-03 The integrity of backups and other restoration assets is verified before using them for restoration NIST-CSF-RC.RP-04 Critical mission functions and cybersecurity risk management are considered to establish post-incident operational norms NIST-CSF-RC.RP-05 The integrity of restored assets is verified, systems and services are restored, and normal operating status is confirmed NIST-CSF-RC.RP-06 The end of incident recovery is declared based on criteria, and incident-related documentation is completed NIST-CSF-RS.MA-05 The criteria for initiating incident recovery are applied 5.29 Information security during disruption 5.30 ICT readiness for business continuity 5.33 Protection of records 7.11 Supporting utilities 7.13 Equipment maintenance 7.5 Protecting against physical and environmental threats 7.8 Equipment siting and protection 8.13 Information backup 8.14 Redundancy of information processing facilities 5.29 Information security during disruption 5.30 ICT readiness for business continuity 5.33 Protection of records 7.11 Supporting utilities 7.13 Equipment maintenance 7.5 Protecting against physical and environmental threats 7.8 Equipment siting and protection 8.13 Information backup 8.14 Redundancy of information processing facilities C5-BCM-01 Top management responsibility C5-OPS-06 Data Backup and Recovery - Concept C5-OPS-07 Data Backup and Recovery - Monitoring C5-PS-01 Physical Security and Environmental Control Requirements C5-PS-02 Redundancy model C5-PS-05 Protection from fire and smoke C5-PS-06 Protection against interruptions caused by power failures and other such risks C5-PS-07 Surveillance of operational and environmental parameters 5.5 Support 6.14 Information security aspects of business continuity management 6.14.1 Information security continuity 6.14.2 Redundancies 6.8.2 Equipment 6.9.3 Backup CIS-11.1 Establish and Maintain a Data Recovery Process CIS-11.2 Perform Automated Backups CIS-11.3 Protect Recovery Data CIS-11.4 Establish and Maintain an Isolated Instance of Recovery Data CIS-11.5 Test Data Recovery ASD37-20 Multi-factor authentication (Essential) ASD37-34 Regular backups (Essential) ASD37-35 Business continuity and disaster recovery plans (Very Good) ASD37-36 System recovery capabilities (Very Good) 4.3.2 Legal and Other Requirements 4.4.1 Resources, Roles, Responsibility, and Authority 4.4.2 Competence, Training, and Awareness 4.4.8 Business Continuity and Recovery ASBv3-BR-3 Monitor backups ASBv3-GS-8 Define and implement backup and recovery strategy BR-1 Ensure regular automated backups BR-2 Protect backup and recovery data 27031-8.1 Exercising and Testing 27031-8.2 Maintaining IRBC 27031-9.3 Management Review 27031-B High availability embedded systems 10.3.3 10.3.3 Audit logs promptly backed up to central secure storage 12.3.1 12.3.1 Targeted risk analysis for flexible-frequency requirements 9.4.1.1 9.4.1.1 Secure storage location for offline backups 9.4.1.2 9.4.1.2 Annual review of offline backup location security PCI-PIN-12 Disaster recovery procedures PCI-PIN-13 Third-party dependency management PCI-PIN-14 Critical service identification PCI-PIN-15 Communication and escalation procedures SSAE18-A1.1 A1.1 - Availability Commitments and Requirements SSAE18-A1.2 A1.2 - Environmental Protections and Recovery SSAE18-A1.3 A1.3 - Recovery Plan Testing SSAE18-CC7.5 CC7.5 - Incident Recovery IM8-DAT.2 Data Protection IM8-DSS.2 Service Reliability Standards IM8-RES.2 Disaster Recovery IM8-RES.4 Resilience Testing E8-BACKUP-ML1 Regular Backups (ML1) E8-BACKUP-ML2 Regular Backups (ML2) E8-BACKUP-ML3 Regular Backups (ML3) API1164-17 Wireless and Field Communications API1164-18 Field Device Security API1164-19 Safety Instrumented Systems Interface CFTC-SS-22 Business Continuity and Disaster Recovery Planning Category CFTC-SS-6 Physical Security and Environmental Controls Category CFTC-SS-8 Business Continuity and Disaster Recovery Plan and Resources FFIEC-11 Business continuity planning and testing FFIEC-12 Disaster recovery procedures FFIEC-14 Critical service identification IEC62443-16 Incident response plan for operational disruptions IEC62443-17 Recovery plan for critical systems IEC62443-20 Exercises and drills for OT incidents ISO27019-16 Incident response plan for operational disruptions ISO27019-18 Reporting obligations to authorities ISO27019-20 Exercises and drills for OT incidents PCI-P2PE-11 Business continuity planning and testing PCI-P2PE-12 Disaster recovery procedures PCI-P2PE-14 Critical service identification PCI-SSF-12 Disaster recovery procedures PCI-SSF-14 Critical service identification PCI-SSF-15 Communication and escalation procedures PICERL-C2 System Backup PICERL-R1 System Restoration PICERL-R2 Security Verification CPS234-14 Definition of Information Security Roles and Responsibilities CPS234-15 Information Security Capability DIQ-1 Data Integration and Interoperability RMD-1 Reference Data Management DORA-Art.12 Backup policies and procedures, restoration and recovery DORA-Art.7 ICT systems, protocols and tools 62351-12 Resilience and security recommendations for DER 62351-13 Cyber-physical generation and storage resilience ISO22316-08 Recovery time and point objectives ISO22316-12 Recovery strategy for critical activities ISO22317-08 Recovery time and point objectives ISO22317-12 Recovery strategy for critical activities ISO22318-08 Recovery time and point objectives ISO22318-12 Recovery strategy for critical activities NFPA1600-5.3 Resource Needs Assessment NFPA1600-6.4 Continuity and Recovery SOC-CY-A1 Availability Commitments SOC-CY-A2 Disaster Recovery SOCI-S30BC Notification of critical cyber security incidents (12 hours) SOCI-S30BD Notification of other cyber security incidents (72 hours) ISMSP-PI-06 Personal Information Destruction ISMSP-SYS-06 Business Continuity and Disaster Recovery OB-API.4 MI Reporting Specification OB-OPS.1 API Availability Requirements SEMD-CS-3 Cyber Resilience SEMD-ER-1 Emergency Exercise and Testing SOC3-AVAILABILITY Availability Criteria ANSSI-HYG-37 Define and Apply a Backup Policy for Critical Components CPS230-P41 BCP Execution Capability and Tolerance Breach Reporting BS65000-RM-03 Leadership and Culture COBIT-BAI04 Managed availability and capacity CAT-D5-4 Resilience planning and testing FEDRAMP-CP-9 System Backup ISO-22320-5.2 Incident management process ISO20000-03 Capacity and availability management ISO-25012-4.13 Availability 27007-5.4 Establishing the Programme Resources 27011-8.6 Data protection and backup ISO27043-23 Backup and recovery procedures A.4.5 System and computing resources ISO21434-23 Backup and recovery procedures ITIL4-03 Capacity and availability management Art.21.2.c Business continuity, backup management, disaster recovery and crisis management 03.08.09 System Backup - Cryptographic Protection SASB-BMI-2 Business Model Resilience UKAI-3 Bias Detection, Fairness, Validation UKOPRES-5 Third-Party Risk, Concentration Risk CERT-1 RRA Certification to EPA CYB-5 Cyber Incident Response Plan Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in A - Availability You are reading one control. How much of SOC 2 have you already done? SOC 2 SOC2-A1.2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.
Query this from an agent The graph holds this control, the 301 it maps to, and the evidence behind each claim, over MCP and REST.