CP-10 Information System Recovery And Reconstitution

Contingency Planning

Low Moderate High

Description

The organization employs mechanisms with supporting procedures to allow the information system to be recovered and reconstituted to a known secure state after a disruption or failure.\n

Supplemental Guidance

Information system recovery and reconstitution to a known secure state means that all system parameters (either default or organization-established) are set to secure values, security-critical patches are reinstalled, security-related configuration settings are reestablished, system documentation and operating procedures are available, application and system software is reinstalled and configured with secure settings, information from the most recent, known secure backups is loaded, and the system is fully tested.\n

Changes from Rev 4

Title changed from 'Information System Recovery and Reconstitution' Parameter adds specific recovery time and recovery point objectives

Enhancements

(1) The organization includes a full recovery and reconstitution of the information system as part of contingency plan testing.\n

Compliance Mappings

ISO 27002:2022

5.295.30

COBIT 2019

DSS04.01DSS04.02DSS04.03DSS04.04DSS04.05DSS04.06DSS04.07DSS04.08

CIS Controls v8

1111.111.3

NIST CSF 2.0

GV.SC-08ID.IM-04PR.IR-02PR.IR-03RCRC.RPRC.RP-01RC.RP-02RC.RP-04RC.RP-05RS.MA-05

SOC 2 TSC

A1.2A1.2-POF1A1.2-POF10A1.2-POF11A1.2-POF2A1.2-POF3A1.2-POF4A1.2-POF5A1.2-POF6CC7.4-POF5CC7.5CC7.5-POF1CC7.5-POF2CC7.5-POF4CC7.5-POF5CC8.1-POF15CC9.1CC9.1-POF1CC9.1-POF2

ISO 17799 (legacy)

14.1.4

COBIT 4.1 (legacy)

DS4.8DS11.5