Does your organization have a process to monitor and verify the performance of restored systems after recovery operations?
Explanation
After system restoration following an incident or disaster, it's crucial to verify that systems are functioning properly and meeting performance expectations. This monitoring helps identify any lingering issues that might affect system functionality, security posture, or data integrity that weren't immediately apparent during the restoration process.
Evidence could include post-restoration monitoring procedures, system performance reports comparing pre-incident and post-restoration metrics, incident response documentation showing verification steps, or screenshots of monitoring dashboards used during the recovery verification phase.
Implementation Example
Monitor the performance of restored systems to verify the adequacy of the restoration
ID: RC.RP-04.353
Context
- Function
- RC: RECOVER
- Category
- RC.RP: Incident Recovery Plan Execution
- Sub-Category
- Critical mission functions and cybersecurity risk management are considered to establish post-incident operational norms
Related questions
- Has your organization established documented procedures to initiate recovery processes during or immediately following security incident response?
- Have all personnel with recovery responsibilities been formally trained on the recovery plans and their specific authorization levels?
- Has your organization defined criteria for selecting recovery actions during incident response, and are these criteria followed when responding to security incidents?
- Does your organization have a process to reassess and update recovery plans based on changes in organizational needs and available resources?
- Does your organization verify restoration assets for integrity issues and indicators of compromise before using them in recovery operations?
- Does your organization use business impact assessments and system categorization records to prioritize the restoration of essential services during recovery operations?

