CP-09 Information System Backup

Contingency Planning

Low Moderate High

Description

The organization conducts backups of user-level and system-level information (including system state information) contained in the information system [Assignment: organization-defined frequency] and protects backup information at the storage location.\n

Supplemental Guidance

The frequency of information system backups and the transfer rate of backup information to alternate storage sites (if so designated) are consistent with the organization’s recovery time objectives and recovery point objectives. While integrity and availability are the primary concerns for system backup information, protecting backup information from unauthorized disclosure is also an important consideration depending on the type of information residing on the backup media and the FIPS 199 impact level. An organizational assessment of risk guides the use of encryption for backup information. The protection of system backup information while in transit is beyond the scope of this control. Related security controls: MP-4, MP-5.\n

Changes from Rev 4

Title changed from 'Information System Backup' Parameter added for conducting backups of user-level information contained in specific system components Removes restrictive control text ‘at storage locations’ Discussion expanded

Enhancements

\n

Compliance Mappings

ISO 27002:2022

8.13

COBIT 2019

APO14.10DSS04.07

CIS Controls v8

11.2

NIST CSF 2.0

PR.DS-11

SOC 2 TSC

A1.2A1.2-POF7A1.2-POF8CC7.5

ISO 17799 (legacy)

10.5.111.7.1

COBIT 4.1 (legacy)

DS4.2DS4.9DS11.5