System Backup

✓ LOW ✓ MODERATE ✓ HIGH
7 Enhancements 1 Overlay 10 Related Controls
Graph
Export ▾

Requirements NIST SOURCE

Discussion (NIST Supplemental Guidance)

System-level information includes system state information, operating system software, middleware, application software, and licenses. User-level information includes information other than system-level information. Mechanisms employed to protect the integrity of system backups include digital signatures and cryptographic hashes. Protection of system backup information while in transit is addressed by MP-5 and SC-8 . System backups reflect the requirements in contingency plans as well as other organizational requirements for backing up information. Organizations may be subject to laws, executive orders, directives, regulations, or policies with requirements regarding specific categories of information (e.g., personal health information). Organizational personnel consult with the senior agency official for privacy and legal counsel regarding such requirements.

Enhancements NIST SOURCE

CP-9(1) Testing for Reliability and Integrity LOW ✓ MODERATE ✓ HIGH

Test backup information [organization-defined frequency] to verify media reliability and information integrity.

Discussion

Organizations need assurance that backup information can be reliably retrieved. Reliability pertains to the systems and system components where the backup information is stored, the operations used to retrieve the information, and the integrity of the information being retrieved. Independent and specialized tests can be used for each of the aspects of reliability. For example, decrypting and transporting (or transmitting) a random sample of backup files from the alternate storage or backup site and comparing the information to the same information at the primary processing site can provide such assurance.

Open full page for CP-9(1) →
CP-9(2) Test Restoration Using Sampling LOW MODERATE ✓ HIGH

Use a sample of backup information in the restoration of selected system functions as part of contingency plan testing.

Discussion

Organizations need assurance that system functions can be restored correctly and can support established organizational missions. To ensure that the selected system functions are thoroughly exercised during contingency plan testing, a sample of backup information is retrieved to determine whether the functions are operating as intended. Organizations can determine the sample size for the functions and backup information based on the level of assurance needed.

Open full page for CP-9(2) →
CP-9(3) Separate Storage for Critical Information LOW MODERATE ✓ HIGH

Store backup copies of [critical system software and other security-related information] in a separate facility or in a fire rated container that is not collocated with the operational system.

Discussion

Separate storage for critical information applies to all critical information regardless of the type of backup storage media. Critical system software includes operating systems, middleware, cryptographic key management systems, and intrusion detection systems. Security-related information includes inventories of system hardware, software, and firmware components. Alternate storage sites, including geographically distributed architectures, serve as separate storage facilities for organizations. Organizations may provide separate storage by implementing automated backup processes at alternative storage sites (e.g., data centers). The General Services Administration (GSA) establishes standards and specifications for security and fire rated containers.

Open full page for CP-9(3) →
CP-9(4) Protection from Unauthorized Modification WITHDRAWN

Withdrawn. Incorporated into CP-9.

CP-9(5) Transfer to Alternate Storage Site LOW MODERATE ✓ HIGH

Transfer system backup information to the alternate storage site [organization-defined time period and transfer rate consistent with the recovery time and recovery point objectives].

Discussion

System backup information can be transferred to alternate storage sites either electronically or by the physical shipment of storage media.

Open full page for CP-9(5) →
CP-9(6) Redundant Secondary System LOW MODERATE HIGH

Conduct system backup by maintaining a redundant secondary system that is not collocated with the primary system and that can be activated without loss of information or disruption to operations.

Discussion

The effect of system backup can be achieved by maintaining a redundant secondary system that mirrors the primary system, including the replication of information. If this type of redundancy is in place and there is sufficient geographic separation between the two systems, the secondary system can also serve as the alternate processing site.

Open full page for CP-9(6) →
CP-9(7) Dual Authorization for Deletion or Destruction LOW MODERATE HIGH

Enforce dual authorization for the deletion or destruction of [backup information].

Discussion

Dual authorization ensures that deletion or destruction of backup information cannot occur unless two qualified individuals carry out the task. Individuals deleting or destroying backup information possess the skills or expertise to determine if the proposed deletion or destruction of information reflects organizational policies and procedures. Dual authorization may also be known as two-person control. To reduce the risk of collusion, organizations consider rotating dual authorization duties to other individuals.

Open full page for CP-9(7) →
CP-9(8) Cryptographic Protection LOW ✓ MODERATE ✓ HIGH

Implement cryptographic mechanisms to prevent unauthorized disclosure and modification of [backup information].

Discussion

The selection of cryptographic mechanisms is based on the need to protect the confidentiality and integrity of backup information. The strength of mechanisms selected is commensurate with the security category or classification of the information. Cryptographic protection applies to system backup information in storage at both primary and alternate locations. Organizations that implement cryptographic mechanisms to protect information at rest also consider cryptographic key management solutions.

Open full page for CP-9(8) →

Implementation Guidance

Engineering Interpretation

Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.

No engineering interpretation has been authored for CP-9 yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.

Assessment

NIST SP 800-53A REV 5.2.0

Assessment Objectives

  1. system components for which to conduct backups of user-level information is defined;
  2. frequency at which to conduct backups of user-level information consistent with recovery time and recovery point objectives is defined;
  3. frequency at which to conduct backups of system-level information consistent with recovery time and recovery point objectives is defined;
  4. frequency at which to conduct backups of system documentation consistent with recovery time and recovery point objectives is defined;
  5. backups of user-level information contained in <CP-09_ODP[01] system components> are conducted <CP-09_ODP[02] frequency>;
  6. backups of system-level information contained in the system are conducted <CP-09_ODP[03] frequency>;
  7. backups of system documentation, including security- and privacy-related documentation are conducted <CP-09_ODP[04] frequency>;
  8. the confidentiality of backup information is protected;
  9. the integrity of backup information is protected;
  10. the availability of backup information is protected.

Examine

[SELECT FROM: Contingency planning policy; procedures addressing system backup; contingency plan; backup storage location(s); system backup logs or records; system security plan; privacy plan; other relevant documents or records].

Interview

[SELECT FROM: Organizational personnel with system backup responsibilities; organizational personnel with information security and privacy responsibilities].

Test

[SELECT FROM: Organizational processes for conducting system backups; mechanisms supporting and/or implementing system backups].

Overlays

OT/ICS Overlay SP 800-82r3

NIST SP 800-82r3 Appendix F, Table 22. Blank baseline means the control/control enhancement is not selected in that initial OT baseline.

LOW

  • Base control: Included (matches standard baseline)

MODERATE

  • Base control: Included (matches standard baseline)
  • Included: (1) (8)

HIGH

  • Base control: Included (matches standard baseline)
  • Included: (1) (2) (3) (5) (8)

STIGs & CCIs

No STIG checks or CCI mappings are currently loaded for CP-9. This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.

Learn more about STIG/CCI integration →

Evidence

Potential Evidence — Derived

Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.

Policy

  • Contingency planning policy
  • contingency plan
  • system security plan
  • privacy plan

Testing

  • Organizational processes for conducting system backups
  • mechanisms supporting and/or implementing system backups

Other Records

  • procedures addressing system backup
  • backup storage location(s)
  • system backup logs or records
  • other relevant documents or records