SOC 2
A - Availability

SOC 2 SOC2-A1.3: A1.3 Testing recovery plan procedures

Procedures in the recovery plan that support system recovery are tested to confirm objectives can be met. Points of focus: business continuity plan testing is performed periodically, with scenarios weighted by how likely and how severe threats are, components across the organisation and its vendors that can impair availability, and unavailability of key people or vendors (vendors added in 2022), and plans are revised from the results; and backup data is tested periodically for integrity and completeness.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 278 controls across 74 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

FedRAMP High · 21 controls

  • CP-10 System Recovery and Reconstitution
  • CP-10(2) System Recovery and Reconstitution | Transaction Recovery (CP-10(2))
  • CP-2 Contingency Plan
  • CP-2(1) Coordinate with Related Plans
  • CP-2(3) Resume Mission and Business Functions
  • CP-4 Contingency Plan Testing
  • CP-4(1) Coordinate with Related Plans
  • CP-6 Alternate Storage Site
  • CP-6(3) Alternate Storage Site | Accessibility (CP-6(3))
  • CP-7 Alternate Processing Site
  • CP-7(2) Alternate Processing Site | Accessibility (CP-7(2))
  • CP-7(3) Alternate Processing Site | Priority of Service (CP-7(3))
  • CP-8 Telecommunications Services
  • CP-9 System Backup
  • CP-9(1) Testing for Reliability and Integrity
  • IR-2 Incident Response Training
  • IR-3 Incident Response Testing
  • IR-7(1) Incident Response Assistance | Automation Support for Availability of Information and Support (IR-7(1))
  • IR-9(3) Information Spillage Response | Post-spill Operations (IR-9(3))
  • MA-6 Timely Maintenance (MA-6)
  • PE-17 Alternate Work Site

FedRAMP Moderate · 21 controls

  • CP-10 System Recovery and Reconstitution
  • CP-10(2) System Recovery and Reconstitution | Transaction Recovery (CP-10(2))
  • CP-2 Contingency Plan
  • CP-2(1) Coordinate with Related Plans
  • CP-2(3) Resume Mission and Business Functions
  • CP-4 Contingency Plan Testing
  • CP-4(1) Coordinate with Related Plans
  • CP-6 Alternate Storage Site
  • CP-6(3) Alternate Storage Site | Accessibility (CP-6(3))
  • CP-7 Alternate Processing Site
  • CP-7(2) Alternate Processing Site | Accessibility (CP-7(2))
  • CP-7(3) Alternate Processing Site | Priority of Service (CP-7(3))
  • CP-8 Telecommunications Services
  • CP-9 System Backup
  • CP-9(1) Testing for Reliability and Integrity
  • IR-2 Incident Response Training
  • IR-3 Incident Response Testing
  • IR-7(1) Incident Response Assistance | Automation Support for Availability of Information and Support (IR-7(1))
  • IR-9(3) Information Spillage Response | Post-spill Operations (IR-9(3))
  • MA-6 Timely Maintenance (MA-6)
  • PE-17 Alternate Work Site

NIST SP 800-53 Rev 5 · 20 controls

  • NIST-CSF-GV.OC-05 Outcomes, capabilities, and services that the organization depends on are understood and communicated
  • NIST-CSF-ID.IM-01 Improvements are identified from evaluations
  • NIST-CSF-ID.IM-04 Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved
  • NIST-CSF-PR.DS-10 The confidentiality, integrity, and availability of data-in-use are protected
  • NIST-CSF-PR.DS-11 Backups of data are created, protected, maintained, and tested
  • NIST-CSF-PR.IR-03 Mechanisms are implemented to achieve resilience requirements in normal and adverse situations
  • NIST-CSF-PR.IR-04 Adequate resource capacity to ensure availability is maintained
  • NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process
  • NIST-CSF-RC.RP-02 Recovery actions are selected, scoped, prioritized, and performed
  • NIST-CSF-RC.RP-03 The integrity of backups and other restoration assets is verified before using them for restoration
  • NIST-CSF-RC.RP-04 Critical mission functions and cybersecurity risk management are considered to establish post-incident operational norms
  • NIST-CSF-RC.RP-05 The integrity of restored assets is verified, systems and services are restored, and normal operating status is confirmed
  • NIST-CSF-RC.RP-06 The end of incident recovery is declared based on criteria, and incident-related documentation is completed
  • NIST-CSF-RS.MA-05 The criteria for initiating incident recovery are applied

ISO 22301:2019 · 11 controls

  • 7.5.1 General
  • 8.2.1 General
  • 8.2.2 Business impact analysis
  • 8.3 Business continuity strategies and solutions
  • 8.3.2 Identification of strategies and solutions
  • 8.3.5 Implementation of solutions
  • 8.4 Business continuity plans and procedures
  • 8.4.1 General
  • 8.4.4 Business continuity plans
  • 8.4.5 Recovery
  • 8.5 Exercise programme

HIPAA Security Rule · 8 controls

NIST SP 800-66 Rev 2 · 8 controls

ISO 27701:2019 · 5 controls

  • 5.6.1 Operational planning and control
  • 6.14 Information security aspects of business continuity management
  • 6.14.1 Information security continuity
  • 6.14.2 Redundancies
  • 6.9.3 Backup
  • ASD37-20 Multi-factor authentication (Essential)
  • ASD37-34 Regular backups (Essential)
  • ASD37-35 Business continuity and disaster recovery plans (Very Good)
  • ASD37-36 System recovery capabilities (Very Good)
  • 4.3.2 Legal and Other Requirements
  • 4.4.1 Resources, Roles, Responsibility, and Authority
  • 4.4.2 Competence, Training, and Awareness
  • 4.4.8 Business Continuity and Recovery

CIS Controls v8 · 4 controls

  • CIS-11.1 Establish and Maintain a Data Recovery Process
  • CIS-11.4 Establish and Maintain an Isolated Instance of Recovery Data
  • CIS-11.5 Test Data Recovery
  • CIS-17.7 Conduct Routine Incident Response Exercises

ISO 27001:2022 · 4 controls

  • 5.24 Information security incident management planning and preparation 
  • 5.29 Information security during disruption
  • 5.30 ICT readiness for business continuity
  • 8.13 Information backup

ISO 27002:2022 · 4 controls

  • 5.29 Information security during disruption
  • 5.30 ICT readiness for business continuity
  • 8.13 Information backup
  • 8.34 Protection of information systems during audit testing

ISO/IEC 27031:2011 · 4 controls

  • 27031-8.1 Exercising and Testing
  • 27031-8.2 Maintaining IRBC
  • 27031-9.3 Management Review
  • 27031-B High availability embedded systems

PCI PIN Security · 4 controls

  • PCI-PIN-12 Disaster recovery procedures
  • PCI-PIN-13 Third-party dependency management
  • PCI-PIN-14 Critical service identification
  • PCI-PIN-15 Communication and escalation procedures
  • SSAE18-A1.1 A1.1 - Availability Commitments and Requirements
  • SSAE18-A1.2 A1.2 - Environmental Protections and Recovery
  • SSAE18-A1.3 A1.3 - Recovery Plan Testing
  • SSAE18-CC7.5 CC7.5 - Incident Recovery
  • IM8-DAT.2 Data Protection
  • IM8-DSS.2 Service Reliability Standards
  • IM8-RES.2 Disaster Recovery
  • IM8-RES.4 Resilience Testing

API 1164 · 3 controls

  • API1164-17 Wireless and Field Communications
  • API1164-18 Field Device Security
  • API1164-19 Safety Instrumented Systems Interface

APRA CPS 234 · 3 controls

  • CPS234-14 Definition of Information Security Roles and Responsibilities
  • CPS234-15 Information Security Capability
  • CPS234-32 Annual Review and Testing of Response Plans
  • CFTC-SS-11 Testing and Review of Business Continuity and Disaster Recovery Capabilities
  • CFTC-SS-22 Business Continuity and Disaster Recovery Planning Category
  • CFTC-SS-9 Next Business Day Recovery Time Objective

DORA · 3 controls

  • DORA-Art.11 Response and recovery
  • DORA-Art.12 Backup policies and procedures, restoration and recovery
  • DORA-Art.24 General requirements for the performance of digital operational resilience testing
  • FFIEC-11 Business continuity planning and testing
  • FFIEC-12 Disaster recovery procedures
  • FFIEC-14 Critical service identification

IEC 62443 · 3 controls

  • IEC62443-16 Incident response plan for operational disruptions
  • IEC62443-17 Recovery plan for critical systems
  • IEC62443-20 Exercises and drills for OT incidents

ISO/IEC 27019:2024 · 3 controls

  • ISO27019-16 Incident response plan for operational disruptions
  • ISO27019-18 Reporting obligations to authorities
  • ISO27019-20 Exercises and drills for OT incidents

NIST SP 1800-32 · 3 controls

PCI DSS 4.0 · 3 controls

  • 10.7.3 10.7.3 Respond promptly to critical security control failures
  • 12.10.2 12.10.2 Annual review and testing of the incident response plan
  • 12.3.1 12.3.1 Targeted risk analysis for flexible-frequency requirements

PCI P2PE · 3 controls

  • PCI-P2PE-11 Business continuity planning and testing
  • PCI-P2PE-12 Disaster recovery procedures
  • PCI-P2PE-14 Critical service identification

PCI SSF · 3 controls

  • PCI-SSF-12 Disaster recovery procedures
  • PCI-SSF-14 Critical service identification
  • PCI-SSF-15 Communication and escalation procedures
  • PICERL-C2 System Backup
  • PICERL-R1 System Restoration
  • PICERL-R2 Security Verification

C5 (Germany) · 2 controls

  • C5-BCM-04 Verification, updating and testing of the business continuity
  • C5-OPS-08 Data Backup and Recovery - Regular Testing
  • DIQ-1 Data Integration and Interoperability
  • RMD-1 Reference Data Management
  • 62351-12 Resilience and security recommendations for DER
  • 62351-13 Cyber-physical generation and storage resilience

ISO 22316 · 2 controls

  • ISO22316-08 Recovery time and point objectives
  • ISO22316-12 Recovery strategy for critical activities

ISO/TS 22317:2021 · 2 controls

  • ISO22317-08 Recovery time and point objectives
  • ISO22317-12 Recovery strategy for critical activities

ISO/TS 22318:2021 · 2 controls

  • ISO22318-08 Recovery time and point objectives
  • ISO22318-12 Recovery strategy for critical activities
  • NFPA1600-5.3 Resource Needs Assessment
  • NFPA1600-6.4 Continuity and Recovery
  • SOC-CY-A1 Availability Commitments
  • SOC-CY-A2 Disaster Recovery
  • SOCI-S30BC Notification of critical cyber security incidents (12 hours)
  • SOCI-S30BD Notification of other cyber security incidents (72 hours)

South Korea ISMS-P · 2 controls

  • ISMSP-PI-06 Personal Information Destruction
  • ISMSP-SYS-06 Business Continuity and Disaster Recovery
  • OB-API.4 MI Reporting Specification
  • OB-OPS.1 API Availability Requirements
  • SEMD-CS-3 Cyber Resilience
  • SEMD-ER-1 Emergency Exercise and Testing
  • E8-BACKUP-ML1 Regular Backups (ML1)
  • ANSSI-HYG-37 Define and Apply a Backup Policy for Critical Components
  • AEO-12 Crisis Management and Incident Recovery
  • BS65000-RM-03 Leadership and Culture

CMMC 2.0 · 1 control

COBIT 2019 · 1 control

  • COBIT-BAI04 Managed availability and capacity
  • CAT-D5-4 Resilience planning and testing

FedRAMP Rev 5 · 1 control

  • FEDRAMP-CP-9 System Backup

ISO 22320:2018 · 1 control

  • ISO-22320-5.2 Incident management process
  • ISO20000-03 Capacity and availability management
  • ISO-25012-4.13 Availability

ISO/IEC 27007:2020 · 1 control

  • 27007-5.4 Establishing the Programme Resources

ISO/IEC 27011:2024 · 1 control

  • 27011-8.6 Data protection and backup

ISO/IEC 27043:2015 · 1 control

  • ISO27043-23 Backup and recovery procedures

ISO/SAE 21434 · 1 control

  • ISO21434-23 Backup and recovery procedures

ITIL 4 · 1 control

  • ITIL4-03 Capacity and availability management

NIS2 Directive · 1 control

  • Art.21.2.c Business continuity, backup management, disaster recovery and crisis management

NIST SP 800-190 · 1 control

SASB Standards · 1 control

  • SASB-BMI-2 Business Model Resilience
  • UKAI-3 Bias Detection, Fairness, Validation
  • UKOPRES-5 Third-Party Risk, Concentration Risk
  • CERT-1 RRA Certification to EPA

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in A - Availability

You are reading one control. How much of SOC 2 have you already done?

SOC 2 SOC2-A1.3 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 278 it maps to, and the evidence behind each claim, over MCP and REST.