RECOVER (RC)¶
Assets and operations affected by a cybersecurity incident are restored
Informative References
- CRI Profile v2.0: RC
- CSF v1.1: RC
- ISO/IEC 27001:2022: Mandatory Clause: None
- ISO/IEC 27001:2022: Annex A Controls: 5.29
- ISO/IEC 27001:2022: Annex A Controls: 8.13
- SCF: BCD-01
- SCF: BCD-12
Incident Recovery Plan Execution (RC.RP)¶
Restoration activities are performed to ensure operational availability of systems and services affected by cybersecurity incidents
Informative References
- CRI Profile v2.0: RC.RP
- CSF v1.1: RC.RP
- ISO/IEC 27001:2022: Mandatory Clause: None
- ISO/IEC 27001:2022: Annex A Controls: 8.13
- NICE Framework: DD-WRL-002
- NICE Framework: IO-WRL-002
- NICE Framework: IO-WRL-005
- NICE Framework: OG-WRL-002
- NICE Framework: OG-WRL-007
- NICE Framework: OG-WRL-009
- NICE Framework: OG-WRL-010
- NICE Framework: OG-WRL-011
- NICE Framework: OG-WRL-014
- NICE Framework: OG-WRL-015
- NICE Framework: PD-WRL-003
- NICE Framework: PD-WRL-004
- SCF: BCD-01
- SCF: BCD-01.4
- SCF: BCD-02
- SCF: BCD-02.1
- SP 800-53 Rev 5.1.1: CP-04
- SP 800-53 Rev 5.1.1: CP-10
- SP 800-53 Rev 5.2.0: CP-04
- SP 800-53 Rev 5.2.0: CP-10
RC.RP-01¶
The recovery portion of the incident response plan is executed once initiated from the incident response process
Implementation Examples
- Ex1: Begin recovery procedures during or after incident response processes
- Ex2: Make all individuals with recovery responsibilities aware of the plans for recovery and the authorizations required to implement each aspect of the plans
Informative References
- AI-SOC: AI-SOC-25
- AI-SOC: AI-SOC-24
- CCMv4.0: BCR-01
- CCMv4.0: SEF-03
- CRI Profile v2.0: RC.RP-01
- CRI Profile v2.0: RC.RP-01.01
- CSF v1.1: RC.RP-1
- CoP: D1
- ISO/IEC 27001:2022: Mandatory Clause: None
- ISO/IEC 27001:2022: Annex A Controls: 5.26
- ISO/IEC 27001:2022: Control 5.29
- NICE Framework: DD-WRL-002
- NICE Framework: IO-WRL-005
- NICE Framework: OG-WRL-002
- NICE Framework: OG-WRL-009
- NICE Framework: OG-WRL-014
- NICE Framework: OG-WRL-015
- NICE Framework: PD-WRL-003
- OWASP Top 10 LLM Applications: LLM04-2025
- PCI DSS: 12.10.1
- PCI DSS: 12.10.3
- PCI DSS: 12.10.2
- SCF: BCD-12
- SP 800-171 Rev 3: 03.06.01
- SP 800-171 Rev 3: 03.06.05
- SP 800-53 Rev 5.1.1: CP-10
- SP 800-53 Rev 5.1.1: IR-04
- SP 800-53 Rev 5.1.1: IR-08
- SP 800-53 Rev 5.2.0: CP-10
- SP 800-53 Rev 5.2.0: IR-04
- SP 800-53 Rev 5.2.0: IR-08
RC.RP-02¶
Recovery actions are selected, scoped, prioritized, and performed
Implementation Examples
- Ex1: Select recovery actions based on the criteria defined in the incident response plan and available resources
- Ex2: Change planned recovery actions based on a reassessment of organizational needs and resources
Informative References
- AI-SOC: AI-SOC-25
- AI-SOC: AI-SOC-06
- CCMv4.0: SEF-06
- CRI Profile v2.0: RC.RP-02
- CRI Profile v2.0: RC.RP-02.01
- CRI Profile v2.0: RC.RP-02.02
- CSF v1.1: RC.RP-1
- Guardian-SDK: GS-PO-02
- ISO/IEC 27001:2022: Mandatory Clause: None
- ISO/IEC 27001:2022: Annex A Controls: 5.26
- ISO/IEC 27001:2022: Control 5.30
- NICE Framework: DD-WRL-002
- NICE Framework: IO-WRL-005
- NICE Framework: OG-WRL-014
- NICE Framework: OG-WRL-015
- NICE Framework: PD-WRL-003
- NICE Framework: PD-WRL-004
- OWASP Top 10 LLM Applications: LLM04-2025
- OWASP Top 10 LLM Applications: LLM10-2025
- PCI DSS: 12.10.1
- PCI DSS: 12.10.2
- PCI DSS: 12.10.6
- PCI DSS: 1.2.3
- PCI DSS: 1.2.4
- SCF: BCD-01
- SCF: BCD-01.4
- SCF: BCD-02
- SCF: BCD-02.1
- SDOS: SDOS-AU-01
- SDOS: SDOS-RM-01
- SP 800-171 Rev 3: 03.06.01
- SP 800-171 Rev 3: 03.06.05
- SP 800-53 Rev 5.1.1: CP-10
- SP 800-53 Rev 5.1.1: IR-04
- SP 800-53 Rev 5.1.1: IR-08
- SP 800-53 Rev 5.2.0: CP-10
- SP 800-53 Rev 5.2.0: IR-04
- SP 800-53 Rev 5.2.0: IR-08
RC.RP-03¶
The integrity of backups and other restoration assets is verified before using them for restoration
Implementation Examples
- Ex1: Check restoration assets for indicators of compromise, file corruption, and other integrity issues before use
Informative References
- AI-SOC: AI-SOC-25
- AI-SOC: AI-SOC-23
- CCMv4.0: BCR-08
- CIS Controls v8.0: 11.5
- CIS Controls v8.1: 11.5
- CRI Profile v2.0: RC.RP-03
- CRI Profile v2.0: RC.RP-03.01
- ISO/IEC 27001:2022: Mandatory Clause: None
- ISO/IEC 27001:2022: Annex A Controls: 8.13
- NICE Framework: DD-WRL-002
- NICE Framework: IO-WRL-002
- NICE Framework: IO-WRL-005
- NICE Framework: OG-WRL-014
- NICE Framework: OG-WRL-015
- NICE Framework: PD-WRL-003
- OWASP Top 10 LLM Applications: LLM04-2025
- PCI DSS: 12.10.1
- PCI DSS: 5.3.2
- PCI DSS: 9.4.1.1
- PCI DSS: 9.4.1.2
- SCF: BCD-13
- SDOS: SDOS-IN-01
- SDOS: SDOS-IN-02
- SP 800-171 Rev 3: 03.08.09
- SP 800-53 Rev 5.1.1: CP-02
- SP 800-53 Rev 5.1.1: CP-04
- SP 800-53 Rev 5.1.1: CP-09
- SP 800-53 Rev 5.2.0: CP-02
- SP 800-53 Rev 5.2.0: CP-04
- SP 800-53 Rev 5.2.0: CP-09
RC.RP-04¶
Critical mission functions and cybersecurity risk management are considered to establish post-incident operational norms
Implementation Examples
- Ex1: Use business impact and system categorization records (including service delivery objectives) to validate that essential services are restored in the appropriate order
- Ex2: Work with system owners to confirm the successful restoration of systems and the return to normal operations
- Ex3: Monitor the performance of restored systems to verify the adequacy of the restoration
Informative References
- AI-SOC: AI-SOC-25
- AI-SOC: AI-SOC-24
- CRI Profile v2.0: RC.RP-04
- CRI Profile v2.0: RC.RP-04.01
- ISO/IEC 27001:2022: Mandatory Clause: 8.1
- ISO/IEC 27001:2022: Annex A Controls: None
- NICE Framework: DD-WRL-002
- NICE Framework: IO-WRL-005
- NICE Framework: OG-WRL-011
- NICE Framework: OG-WRL-014
- NICE Framework: OG-WRL-015
- NICE Framework: PD-WRL-003
- OWASP Top 10 LLM Applications: LLM09-2025
- PCI DSS: 12.10.1
- PCI DSS: 12.5.1
- PCI DSS: 1.2.3
- PCI DSS: 1.2.4
- PCI DSS: 10.2.1
- SCF: BCD-01
- SCF: BCD-01.4
- SCF: BCD-02
- SCF: BCD-02.1
- SP 800-171 Rev 3: 03.06.05
- SP 800-171 Rev 3: 03.15.01
- SP 800-53 Rev 5.1.1: PM-08
- SP 800-53 Rev 5.1.1: PM-09
- SP 800-53 Rev 5.1.1: PM-11
- SP 800-53 Rev 5.1.1: IR-01
- SP 800-53 Rev 5.1.1: IR-08
- SP 800-53 Rev 5.2.0: PM-08
- SP 800-53 Rev 5.2.0: PM-09
- SP 800-53 Rev 5.2.0: PM-11
- SP 800-53 Rev 5.2.0: IR-01
- SP 800-53 Rev 5.2.0: IR-08
RC.RP-05¶
The integrity of restored assets is verified, systems and services are restored, and normal operating status is confirmed
Implementation Examples
- Ex1: Check restored assets for indicators of compromise and remediation of root causes of the incident before production use
- Ex2: Verify the correctness and adequacy of the restoration actions taken before putting a restored system online
Informative References
- AI-SOC: AI-SOC-25
- AI-SOC: AI-SOC-02
- CRI Profile v2.0: RC.RP-05
- CRI Profile v2.0: RC.RP-05.01
- CRI Profile v2.0: RC.RP-05.02
- ISO/IEC 27001:2022: Mandatory Clause: None
- ISO/IEC 27001:2022: Annex A Controls: 5.26
- NICE Framework: DD-WRL-002
- NICE Framework: IO-WRL-002
- NICE Framework: IO-WRL-005
- NICE Framework: OG-WRL-014
- NICE Framework: OG-WRL-015
- NICE Framework: PD-WRL-003
- NICE Framework: PD-WRL-004
- OWASP Top 10 LLM Applications: LLM03-2025
- OWASP Top 10 LLM Applications: LLM04-2025
- PCI DSS: 11.4.4
- PCI DSS: 6.2.3
- PCI DSS: 10.4.1
- SCF: BCD-12
- SDOS: SDOS-IA-02
- SDOS: SDOS-IN-01
- SDOS: SDOS-IN-03
- SP 800-53 Rev 5.1.1: CP-10
- SP 800-53 Rev 5.2.0: CP-10
RC.RP-06¶
The end of incident recovery is declared based on criteria, and incident-related documentation is completed
Implementation Examples
- Ex1: Prepare an after-action report that documents the incident itself, the response and recovery actions taken, and lessons learned
- Ex2: Declare the end of incident recovery once the criteria are met
Informative References
- CRI Profile v2.0: RC.RP-06
- CRI Profile v2.0: RC.RP-06.01
- ISO/IEC 27001:2022: Mandatory Clause: None
- ISO/IEC 27001:2022: Annex A Controls: 5.27
- ISO/IEC 27001:2022: Annex A Controls: 8.13
- NICE Framework: DD-WRL-002
- NICE Framework: IO-WRL-005
- NICE Framework: OG-WRL-007
- NICE Framework: OG-WRL-010
- NICE Framework: OG-WRL-014
- NICE Framework: OG-WRL-015
- NICE Framework: PD-WRL-003
- PCI DSS: 12.10.6
- PCI DSS: 12.10.2
- PCI DSS: 10.5.1
- SCF: IRO-02
- SCF: IRO-09
- SDOS: SDOS-AU-01
- SDOS: SDOS-IN-01
- SDOS: SDOS-IN-03
- SP 800-171 Rev 3: 03.06.01
- SP 800-171 Rev 3: 03.06.05
- SP 800-53 Rev 5.1.1: IR-04
- SP 800-53 Rev 5.1.1: IR-08
- SP 800-53 Rev 5.2.0: IR-04
- SP 800-53 Rev 5.2.0: IR-08
Incident Recovery Communication (RC.CO)¶
Restoration activities are coordinated with internal and external parties
Informative References
- CRI Profile v2.0: RC.CO
- CSF v1.1: RC.CO
- ISO/IEC 27001:2022: Mandatory Clause: 8.1
- ISO/IEC 27001:2022: Annex A Controls: 5.28
- NICE Framework: IO-WRL-005
- NICE Framework: OG-WRL-006
- NICE Framework: OG-WRL-007
- NICE Framework: OG-WRL-008
- NICE Framework: OG-WRL-010
- NICE Framework: OG-WRL-011
- NICE Framework: OG-WRL-015
- NICE Framework: PD-WRL-003
- SCF: BCD-01.1
- SCF: BCD-01.2
- SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy
- SP-800-37 Rev 2: RMF Monitor Step: TASK M-3 Ongoing Risk Response
RC.CO-01¶
[Withdrawn: Incorporated into RC.CO-04]
RC.CO-02¶
[Withdrawn: Incorporated into RC.CO-04]
RC.CO-03¶
Recovery activities and progress in restoring operational capabilities are communicated to designated internal and external stakeholders
Implementation Examples
- Ex1: Securely share recovery information, including restoration progress, consistent with response plans and information sharing agreements
- Ex2: Regularly update senior leadership on recovery status and restoration progress for major incidents
- Ex3: Follow the rules and protocols defined in contracts for incident information sharing between the organization and its suppliers
- Ex4: Coordinate crisis communication between the organization and its critical suppliers
Informative References
- CRI Profile v2.0: RC.CO-03
- CRI Profile v2.0: RC.CO-03.01
- CRI Profile v2.0: RC.CO-03.02
- CSF v1.1: RC.CO-3
- ISO/IEC 27001:2022: Mandatory Clause: 7.4
- ISO/IEC 27001:2022: Annex A Controls: 5.28
- NICE Framework: IO-WRL-005
- NICE Framework: OG-WRL-006
- NICE Framework: OG-WRL-007
- NICE Framework: OG-WRL-008
- NICE Framework: OG-WRL-010
- NICE Framework: OG-WRL-011
- NICE Framework: OG-WRL-015
- NICE Framework: PD-WRL-003
- PCI DSS: 12.10.1
- PCI DSS: 12.10.3
- PCI DSS: 12.8.2
- PCI DSS: 12.8.4
- SDOS: SDOS-AU-01
- SDOS: SDOS-AU-03
- SP 800-171 Rev 3: 03.06.01
- SP 800-171 Rev 3: 03.06.02
- SP 800-221A: GV.CO-1
- SP 800-53 Rev 5.1.1: IR-04
- SP 800-53 Rev 5.1.1: IR-06
- SP 800-53 Rev 5.1.1: SR-08
- SP 800-53 Rev 5.2.0: IR-04
- SP 800-53 Rev 5.2.0: IR-06
- SP 800-53 Rev 5.2.0: SR-08
RC.CO-04¶
Public updates on incident recovery are shared using approved methods and messaging
Implementation Examples
- Ex1: Follow the organization's breach notification procedures for recovering from a data breach incident
- Ex2: Explain the steps being taken to recover from the incident and to prevent a recurrence
Informative References
- AI-SOC: AI-SOC-30
- AI-SOC: AI-SOC-12
- CIS Controls v8.0: 17.2
- CIS Controls v8.0: 17.6
- CIS Controls v8.1: 17.2
- CIS Controls v8.1: 17.6
- CRI Profile v2.0: RC.CO-04
- CRI Profile v2.0: RC.CO-04.01
- CSF v1.1: RC.CO-1
- CSF v1.1: RS.CO-2
- ISO/IEC 27001:2022: Mandatory Clause: 7.4
- ISO/IEC 27001:2022: Annex A Controls: None
- NICE Framework: OG-WRL-006
- NICE Framework: OG-WRL-007
- NICE Framework: OG-WRL-008
- NICE Framework: OG-WRL-010
- NICE Framework: OG-WRL-015
- NICE Framework: PD-WRL-003
- OWASP Top 10 LLM Applications: LLM02-2025
- PCI DSS: 12.10.1
- PCI DSS: 12.10.3
- SCF: IRO-16
- SP 800-171 Rev 3: 03.06.01
- SP 800-221A: GV.CO-1
- SP 800-53 Rev 5.1.1: CP-02
- SP 800-53 Rev 5.1.1: IR-04
- SP 800-53 Rev 5.2.0: CP-02
- SP 800-53 Rev 5.2.0: IR-04
Improvements (RC.IM)¶
[Withdrawn: Incorporated into ID.IM]
RC.IM-01¶
[Withdrawn: Incorporated into ID.IM-03, ID.IM-04]
RC.IM-02¶
[Withdrawn: Incorporated into ID.IM-03]