NIST CSF · Domain 5
Recover
About 10% of the exam
Recover categories in 2.0
- Recovery plan executed
- Restore in dependency order
- Verify integrity
- Confirm the attacker is gone
- Return to production
- Communicate restoration
- Declare recovery complete
- RC.RP
- incident recovery plan execution
- RC.CO
- incident recovery communication
- Purpose
- restore assets and normal operations
- Scope
- the plan, the order, the verification
- Trigger
- response has contained the incident
- Closure
- declared once service is normal
Recovery is not finished when systems boot; it is finished when they are verified clean and genuinely back in service
Plans and their scope
- Business continuity
- keeping the business running
- Disaster recovery
- restoring the IT infrastructure
- Incident recovery
- restoring after a cyber event
- Crisis communication
- who says what publicly
- Relationship
- nested plans, one activation path
RTO and RPO
- RTO
- how long restoration may take
- RPO
- how much data may be lost
- Set by
- the business impact analysis
- Tested against
- actual measured restore times
- Mismatch
- plan promises what backups cannot
Restoration order
- Map dependencies before the incident
- Identity and directory services come first
- Then network and shared platforms
- Then the highest value business services
- Validate each tier before the next
- Document the order and rehearse it
Verifying integrity
- Confirm backups predate the compromise
- Scan restored systems before connecting
- Reconcile data against authoritative sources
- Rotate credentials and keys after restore
- Watch restored systems more closely
- A restored bad configuration repeats the incident
Automation in recovery
- Infrastructure as code rebuilds consistently
- Automation brings speed and repeatability
- It can also restore the compromise
- Human checkpoints between automated stages
- Test automation in a clean environment
Recovery communication
- Internal staff told what to expect
- Customers given accurate restoration timelines
- Never promise dates you cannot meet
- Public statements coordinated with legal
- Regulators updated as recovery progresses
- Explain what customers should do themselves
- Record every external statement made
Understating the impact in the first statement costs more trust later than a cautious one ever does
Recovery failures
- Backups restored, malware restored with them
- No dependency map, restoration order guessed
- Plan never exercised from end to end
- Backup credentials shared with production
- Recovery time promised without measurement
- Data reconciled by assumption, not evidence
- Recovery declared before verification finished
Exercising recovery
- Tabletop for decisions and roles
- Technical restore test for real times
- Full failover for critical services
- Exercise under realistic constraints
- Record and fix what failed
Third party dependencies
- Provider recovery times written into contracts
- Test provider failover where possible
- Know their notification commitments
- Plan for their outage too
- Alternate provider identified in advance
Improving after recovery
- Measure actual against target times
- Feed gaps into the improvement plan
- Update the current profile honestly
- Revise the strategy where it failed
- Improvement outcomes belong to ID.IM
Rapid recall: recovery terms
- RTO
- target time to restore
- RPO
- acceptable data loss window
- Maximum tolerable outage
- the longest the business survives
- Hot site
- ready to run immediately
- Warm site
- equipped, needs data and setup
- Cold site
- space and power only
Reference strip: plan, order, verify, communicate, learn
Plan
- Written, approved, exercised
- RTO and RPO from impact analysis
- Alternate sites and providers named
Order
- Dependencies mapped in advance
- Identity and network restored first
- Each tier validated before the next
Verify
- Backups predate the compromise
- Scan before reconnecting
- Credentials and keys rotated
Communicate
- Staff, customers, regulators updated
- Timelines honest and revisable
- Statements recorded and coordinated
Learn
- Actual times against targets
- Strategy revised where it failed
- Improvements tracked in ID.IM
Quick exam traps
- Trap: Recovery is complete once systems are back online
- Trap: The most recent backup is always the right one to restore
- Trap: Automated recovery removes the need for verification
- Trap: Recovery time objectives can be set without testing a restore
- Trap: Recovery communication is only a public relations task
- Trap: Lessons from recovery belong to the Recover function
cybercertprep.com · original revision sheet written from the public body of knowledge