Has your organization assessed and documented how incident recovery activities might impact normal business operations?
Explanation
Recovery impact on the business is what reviewers want analyzed: whether you have assessed and documented how incident recovery activities might disrupt normal operations. For example, restoring systems from backups might require temporary service outages, isolating infected systems could impact connected business processes, or redirecting staff to incident response might delay other critical functions.
Evidence could include a business impact analysis document, incident response playbooks that include operational impact assessments, or recovery time objective (RTO) documentation that accounts for operational disruptions during recovery activities.
Implementation Example
Take the possible operational disruption of incident recovery activities into account
ID: RS.MA-05.320
Context
- Function
- RS: RESPOND
- Category
- RS.MA: Incident Management
- Sub-Category
- The criteria for initiating incident recovery are applied
Related questions
- Do your detection technologies automatically report confirmed security incidents to appropriate personnel or systems?
- Does your organization have a formal agreement with an external incident response provider that can be engaged when needed?
- Does your organization assign a designated incident lead for each security incident?
- Does your organization have a process to activate additional cybersecurity plans (such as business continuity and disaster recovery) during incident response when needed?
- Does your organization have a process to initially screen and validate incident reports to determine if they are cybersecurity-related and require incident response procedures?
- Does your organization have documented criteria for estimating the severity of security incidents?

