RC.RP-06.357
Has your organization established formal criteria for declaring the end of an incident recovery phase?
Explanation
Defining clear criteria for when an incident is considered resolved helps ensure all necessary recovery steps are completed and normal operations can resume. These criteria might include system stability for a defined period, confirmation that vulnerabilities have been addressed, verification that no malicious activity remains, and completion of all required documentation.
Evidence could include a documented incident response plan with a specific section on recovery completion criteria, post-incident review templates that include a formal sign-off process, or examples of closed incident tickets showing the criteria that were met before closure.
Implementation Example
Declare the end of incident recovery once the criteria are met
ID: RC.RP-06.357
Context
- Function
- RC: RECOVER
- Category
- RC.RP: Incident Recovery Plan Execution
- Sub-Category
- The end of incident recovery is declared based on criteria, and incident-related documentation is completed
Related questions
- Has your organization established documented procedures to initiate recovery processes during or immediately following security incident response?
- Have all personnel with recovery responsibilities been formally trained on the recovery plans and their specific authorization levels?
- Has your organization defined criteria for selecting recovery actions during incident response, and are these criteria followed when responding to security incidents?
- Does your organization have a process to reassess and update recovery plans based on changes in organizational needs and available resources?
- Does your organization verify restoration assets for integrity issues and indicators of compromise before using them in recovery operations?
- Does your organization use business impact assessments and system categorization records to prioritize the restoration of essential services during recovery operations?