|
controlCP-9

System Backup (CP-9)

Conduct backups of user-level information contained in [organization-defined] [organization-defined]; Conduct backups of system-level information contained in the system [organization-defined]; Conduct backups of system documentation, including security- and privacy-related documentation [organization-defined] ; and Protect the confidentiality, integrity, and availability of backup information.

Security Baselines

LOWMODERATEHIGH
contingencydisaster-recoverybusiness-continuity

Why These Connect

Maps To10

These are equivalent or closely aligned requirements in other frameworks.

Baselined In3

This control is included in the linked security baseline (LOW, MODERATE, or HIGH).

Supports32

These related controls work together — a change to one may affect the others.

Mitigates2

This control helps defend against or reduce the risk of the linked threat technique.

Enhances8

These enhancements add specific capabilities or refinements to the base control.

Threat Coverage(2 ATT&CK techniques)

Cross-Framework Mappings(10)

PR.DS-01PR.DS-01Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
PR.DS-10PR.DS-10Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
PR.DS-11PR.DS-11Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
RC.RP-03RC.RP-03Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ISO 27001ISO/IEC 27001:20223 mappingsFinal
NIST OLIR informative reference — SP 800-53 Rev 5 to ISO/IEC 27001:2022
HIPAAHIPAA Security Rule4 mappingsFinal
NIST OLIR informative reference — HIPAA Security Rule to SP 800-53 Rev 5
PR.DS-01PR.DS-01Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
PR.DS-10PR.DS-10Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
PR.DS-11PR.DS-11Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
RC.RP-03RC.RP-03Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5

Organization-Defined Parameters(4)

Assignmentorganization-defined system components
Assignmentorganization-defined frequency
Assignmentorganization-defined frequency
Assignmentorganization-defined frequency

Control Enhancements(8)