|
controlCP-10
System Recovery and Reconstitution (CP-10)
Provide for the recovery and reconstitution of the system to a known state within [organization-defined] after a disruption, compromise, or failure.
Security Baselines
LOWMODERATEHIGH
contingencydisaster-recoverybusiness-continuity
Why These Connect
Maps To10
These are equivalent or closely aligned requirements in other frameworks.
Baselined In3
This control is included in the linked security baseline (LOW, MODERATE, or HIGH).
Supports29
These related controls work together — a change to one may affect the others.
Mitigates2
This control helps defend against or reduce the risk of the linked threat technique.
Enhances6
These enhancements add specific capabilities or refinements to the base control.
Related Controls(17)
CM-2Baseline Configuration (CM-2)
LMH
CM-6Configuration Settings (CM-6)LMH
CP-2Contingency Plan (CP-2)LMH
CP-6Alternate Storage Site (CP-6)MH
CP-7Alternate Processing Site (CP-7)MH
CP-9System Backup (CP-9)LMH
CP-4Contingency Plan Testing (CP-4)LMH
IR-4Incident Handling (IR-4)LMH
SA-8Security and Privacy Engineering Principles (SA-8)LMH
SC-24Fail in Known State (SC-24)H
SI-13Predictable Failure Prevention (SI-13)MP-2Media Access (MP-2)LMH
MP-4Media Storage (MP-4)MH
PE-3Physical Access Control (PE-3)LMH
PE-6Monitoring Physical Access (PE-6)LMH
SA-24Design For Cyber Resiliency (SA-24)SC-7Boundary Protection (SC-7)LMH
Threat Coverage(2 ATT&CK techniques)
Cross-Framework Mappings(10)
RC.RPIncident Recovery Plan Execution (RC.RP)Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
RC.RP-01RC.RP-01Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
RC.RP-02RC.RP-02Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
RC.RP-05RC.RP-05Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ISO 27001ISO/IEC 27001:20221 mappingFinal
NIST OLIR informative reference — SP 800-53 Rev 5 to ISO/IEC 27001:2022
HIPAAHIPAA Security Rule2 mappingsFinal
NIST OLIR informative reference — HIPAA Security Rule to SP 800-53 Rev 5
RC.RPIncident Recovery Plan Execution (RC.RP)Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
RC.RP-01RC.RP-01Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
RC.RP-02RC.RP-02Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
RC.RP-05RC.RP-05Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
Organization-Defined Parameters(2)
Assignmentorganization-defined time period
Assignmentorganization-defined time period