RC.RP-01.346
Has your organization established documented procedures to initiate recovery processes during or immediately following security incident response?
Explanation
This question assesses whether your organization has formalized procedures that link incident response activities with recovery operations, ensuring business continuity. Recovery procedures should be triggered at appropriate points during incident handling to minimize downtime and data loss, rather than waiting until all response activities are complete. Evidence could include a documented incident response plan with clearly defined recovery trigger points, runbooks that show the handoff between incident response and recovery teams, or post-incident reports demonstrating how recovery procedures were initiated during recent security incidents.
Implementation Example
Begin recovery procedures during or after incident response processes
ID: RC.RP-01.346
Context
- Function
- RC: RECOVER
- Category
- RC.RP: Incident Recovery Plan Execution
- Sub-Category
- The recovery portion of the incident response plan is executed once initiated from the incident response process

